Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21535

21535 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-46236 WordPress HTML Forms plugin <= 1.5.2 - Cross Site Scripting (XSS) Vulnerability — HTML Forms 6.5 Medium2025-04-22
CVE-2025-46235 WordPress SKT Blocks – Gutenberg based Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) Vulnerability — SKT Blocks 6.5 Medium2025-04-22
CVE-2025-46233 WordPress Sirv plugin <= 7.5.3 - Cross Site Scripting (XSS) Vulnerability — Sirv 6.5 Medium2025-04-22
CVE-2025-46229 WordPress Textmetrics plugin <= 3.6.2 - Cross Site Scripting (XSS) Vulnerability — Textmetrics 5.9 Medium2025-04-22
CVE-2025-46227 WordPress Custom Related Posts plugin <= 1.7.4 - Cross Site Scripting (XSS) Vulnerability — Custom Related Posts 6.5 Medium2025-04-22
CVE-2025-46228 WordPress Event post plugin <= 5.9.11 - Cross Site Scripting (XSS) Vulnerability — Event post 6.5 Medium2025-04-22
CVE-2025-46226 WordPress MPL-Publisher plugin <= 2.18.0 - Cross Site Scripting (XSS) Vulnerability — MPL-Publisher 6.5 Medium2025-04-22
CVE-2025-46225 WordPress Post in page for Elementor plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability — Post in page for Elementor 6.5 Medium2025-04-22
CVE-2025-3814 Tax Switch for WooCommerce <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via class-name Parameter — Tax Switch for WooCommerce 6.4 Medium2025-04-22
CVE-2025-2839 WP Import Export Lite <= 3.9.27 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting — WP Import Export Lite 6.4 Medium2025-04-22
CVE-2024-12863 Stored XSS in Discussions functionality — OpenText Content Management 5.4 -2025-04-21
CVE-2025-3840 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') — OVA based Connect 6.1 -2025-04-21
CVE-2025-3826 SourceCodester Web-based Pharmacy Product Management System add-supplier.php cross site scripting — Web-based Pharmacy Product Management System 2.4 Low2025-04-20
CVE-2025-3825 SourceCodester Web-based Pharmacy Product Management System add-category.php cross site scripting — Web-based Pharmacy Product Management System 2.4 Low2025-04-20
CVE-2025-3824 SourceCodester Web-based Pharmacy Product Management System add-product.php cross site scripting — Web-based Pharmacy Product Management System 2.4 Low2025-04-20
CVE-2025-3823 SourceCodester Web-based Pharmacy Product Management System add-stock.php cross site scripting — Web-based Pharmacy Product Management System 2.4 Low2025-04-20
CVE-2025-3822 SourceCodester Web-based Pharmacy Product Management System changepassword.php cross site scripting — Web-based Pharmacy Product Management System 2.4 Low2025-04-20
CVE-2025-3821 SourceCodester Web-based Pharmacy Product Management System add-admin.php cross site scripting — Web-based Pharmacy Product Management System 2.4 Low2025-04-20
CVE-2025-43954 QMarkdown 安全漏洞 — QMarkdown 4.9 Medium2025-04-20
CVE-2020-36844 KnowBe4 Security Awareness Training 安全漏洞 — Security Awareness Training 6.1 Medium2025-04-20
CVE-2025-3806 dazhouda lecms Edit Profile admin cross site scripting — lecms 2.4 Low2025-04-19
CVE-2025-3801 songquanpeng one-api System Setting cross site scripting — one-api 2.4 Low2025-04-19
CVE-2025-3661 SB Chart block <= 1.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter — SB Chart block 6.4 Medium2025-04-19
CVE-2025-3809 Debug Log Manager <= 2.3.4 - Unauthenticated Stored Cross-Site Scripting — Debug Log Manager – Conveniently Monitor and Inspect Errors 7.2 High2025-04-19
CVE-2025-1457 Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) <= 5.10.28 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting — Element Pack – Widgets, Templates & Addons for Elementor 6.4 Medium2025-04-19
CVE-2025-3275 Themesflat Addons For Elementor <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting — Themesflat Addons For Elementor 6.4 Medium2025-04-19
CVE-2025-3795 DaiCuo SEO Optimization Settings Section cross site scripting — DaiCuo 2.4 Low2025-04-18
CVE-2025-3789 baseweb JSite save cross site scripting — JSite 3.5 Low2025-04-18
CVE-2025-3788 baseweb JSite save cross site scripting — JSite 3.5 Low2025-04-18
CVE-2025-3106 LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Table of Contents Widget — LA-Studio Element Kit for Elementor 6.4 Medium2025-04-18

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21535 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.