Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21532

21532 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-5807 Gwolle Guestbook <= 4.9.2 - Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parameter — Gwolle Guestbook 6.1 Medium2025-07-10
CVE-2025-4406 wpForo Forum <= 2.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar — wpForo Forum 5.4 Medium2025-07-10
CVE-2025-6976 Events Manager <= 7.0.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes — Events Manager – Calendar, Bookings, Tickets, and more! 6.4 Medium2025-07-09
CVE-2025-6975 Event Manager <= 7.0.3 - Reflected Cross-Site Scripting via `calendar_header` Parameter — Events Manager – Calendar, Bookings, Tickets, and more! 6.1 Medium2025-07-09
CVE-2025-7059 Simple Featured Image <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via slideshow Parameter — Simple Featured Image 6.4 Medium2025-07-09
CVE-2025-5678 Kadence Blocks – Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor 6.4 Medium2025-07-09
CVE-2025-49534 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager 5.4 Medium2025-07-08
CVE-2025-49547 Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) — Adobe Experience Manager 5.4 Medium2025-07-08
CVE-2025-49542 ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79) — ColdFusion 5.2 Medium2025-07-08
CVE-2025-49541 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusion 4.3 Medium2025-07-08
CVE-2025-49543 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusion 4.3 Medium2025-07-08
CVE-2025-49540 ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) — ColdFusion 4.3 Medium2025-07-08
CVE-2023-43039 IBM OpenPages with Watson cross-site scripting — OpenPages with Watson 6.1 Medium2025-07-08
CVE-2025-7363 TitleIcon: Stored Cross-Site Scripting (XSS) via #titleicon_unicode parser function — Mediawiki - TitleIcon extension 5.4AIMediumAI2025-07-08
CVE-2025-7362 MsUpload: Stored Cross-Site Scripting (XSS) via unsanitized msu-continue system message — Mediawiki - MsUpload extension 5.4AIMediumAI2025-07-08
CVE-2025-53479 CheckUser: Reflected Cross-Site Scripting (XSS) in Special:CheckUser via unsanitized internationalized message — Mediawiki - CheckUser extension 6.1AIMediumAI2025-07-08
CVE-2025-2793 IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting — Sterling B2B Integrator 5.4 Medium2025-07-08
CVE-2025-53480 CheckUser: Reflected Cross-Site Scripting (XSS) in Special:Investigate (Account information tab) via unsanitized i18n messages — Mediawiki - CheckUser extension 6.1AIMediumAI2025-07-08
CVE-2025-3630 IBM Sterling B2B Integrator and IBM Sterling File Gateway cross-site scripting — Sterling B2B Integrator 6.4 Medium2025-07-08
CVE-2025-7182 itsourcecode Student Transcript Processing System edit.php cross site scripting — Student Transcript Processing System 4.3 Medium2025-07-08
CVE-2025-40721 Reflected Cross-site Scripting (XSS) vulnerability in Quiter Gateway — Quiter Gateway (Java WAR on Apache Tomcat) 6.1AIMediumAI2025-07-08
CVE-2025-40720 Reflected Cross-site Scripting (XSS) vulnerability in Quiter Gateway — Quiter Gateway (Java WAR on Apache Tomcat) 6.1AIMediumAI2025-07-08
CVE-2025-40719 Reflected Cross-site Scripting (XSS) vulnerability in Quiter Gateway — Quiter Gateway (Java WAR on Apache Tomcat) 6.1AIMediumAI2025-07-08
CVE-2025-42956 Multiple vulnerabilities in SAP NetWeaver Application Server ABAP — SAP NetWeaver Application Server ABAP 6.1 Medium2025-07-08
CVE-2025-6743 WoodMart <= 8.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting — Woodmart 6.4 Medium2025-07-08
CVE-2025-5537 Lightbox & Modal Popup WordPress Plugin – FooBox <= 2.7.34 - Authenticated (Author+) Stored Cross-Site Scripting — Lightbox & Modal Popup WordPress Plugin – FooBox 6.4 Medium2025-07-08
CVE-2025-6244 Essential Addons for Elementor – Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets — Essential Addons for Elementor – Popular Elementor Templates & Widgets 6.4 Medium2025-07-08
CVE-2025-5570 AI Engine <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter — AI Engine – The Chatbot, AI Framework & MCP for WordPress 5.4 Medium2025-07-08
CVE-2025-42973 Cross-Site Scripting (XSS) vulnerability in SAP Data Services (DQ Report) — SAP Data Services (DQ Report) 5.4 Medium2025-07-08
CVE-2025-42969 Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform — SAP NetWeaver Application Server ABAP and ABAP Platform 6.1 Medium2025-07-08

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21532 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.