Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21498

21498 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-25025 WordPress VikRestaurants plugin <= 1.5.2 - Reflected Cross Site Scripting (XSS) vulnerability — VikRestaurants 7.1 High2026-03-25
CVE-2026-25018 WordPress NaturaLife Extensions plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability — NaturaLife Extensions 7.1 High2026-03-25
CVE-2026-25013 WordPress Phox Hosting plugin <= 2.0.8 - Reflected Cross Site Scripting (XSS) vulnerability — Phox Hosting 7.1 High2026-03-25
CVE-2026-24983 WordPress UpSolution Core plugin <= 8.41 - Reflected Cross Site Scripting (XSS) vulnerability — UpSolution Core 7.1 High2026-03-25
CVE-2026-24980 WordPress Visionary Core plugin <= 1.4.9 - Reflected Cross Site Scripting (XSS) vulnerability — Visionary Core 7.1 High2026-03-25
CVE-2026-24975 WordPress Organici Library plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerability — Organici Library 7.1 High2026-03-25
CVE-2026-24979 WordPress Jobica Core plugin <= 1.4.1 - Reflected Cross Site Scripting (XSS) vulnerability — Jobica Core 7.1 High2026-03-25
CVE-2026-24973 WordPress CitiLights theme <= 3.7.1 - Reflected Cross Site Scripting (XSS) vulnerability — CitiLights 7.1 High2026-03-25
CVE-2026-24391 WordPress Car Dealer theme <= 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability — Car Dealer 7.1 High2026-03-25
CVE-2026-24370 WordPress The Grid plugin < 2.8.0 - Cross Site Scripting (XSS) vulnerability — The Grid 6.5 Medium2026-03-25
CVE-2026-23979 WordPress Gyan Elements plugin <= 2.2.1 - Reflected Cross Site Scripting (XSS) vulnerability — Gyan Elements 7.1 High2026-03-25
CVE-2026-23807 WordPress WP Telegram Widget and Join Link plugin <= 2.2.13 - Reflected Cross Site Scripting (XSS) vulnerability — WP Telegram Widget and Join Link 7.1 High2026-03-25
CVE-2026-23973 WordPress Golo theme < 1.7.5 - Reflected Cross Site Scripting (XSS) vulnerability — Golo 7.1 High2026-03-25
CVE-2026-22524 WordPress Legacy Admin plugin <= 9.5 - Reflected Cross Site Scripting (XSS) vulnerability — Legacy Admin 7.1 High2026-03-25
CVE-2026-22523 WordPress Ultra WordPress Admin plugin <= 11.7 - Reflected Cross Site Scripting (XSS) vulnerability — Ultra WordPress Admin 7.1 High2026-03-25
CVE-2026-22520 WordPress Handmade Framework plugin <= 3.9 - Reflected Cross Site Scripting (XSS) vulnerability — Handmade Framework 7.1 High2026-03-25
CVE-2026-22491 WordPress My auctions allegro plugin <= 3.6.35 - Cross Site Scripting (XSS) vulnerability — My auctions allegro 7.1 High2026-03-25
CVE-2025-69096 WordPress Zorka theme <= 1.5.7 - Reflected Cross Site Scripting (XSS) vulnerability — Zorka 7.1 High2026-03-25
CVE-2026-20108 Cisco Catalyst SD-WAN Manager(Cisco SD-WAN vManage) 跨站脚本漏洞 — Cisco Catalyst SD-WAN Manager 5.4 Medium2026-03-25
CVE-2026-20112 Cisco IOS XE Software 跨站脚本漏洞 — Cisco IOS XE Software 4.8 Medium2026-03-25
CVE-2026-3218 Responsive Favicons - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-019 — Responsive Favicons 6.1 -2026-03-25
CVE-2026-3217 SAML SSO - Service Provider - Critical - Cross-site scripting - SA-CONTRIB-2026-018 — SAML SSO - Service Provider 6.1 -2026-03-25
CVE-2026-3215 Islandora - Moderately critical - Arbitrary file upload, Cross-site scripting - SA-CONTRIB-2026-016 — Islandora 6.1 -2026-03-25
CVE-2026-3213 Anti-Spam by CleanTalk - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-014 — Anti-Spam by CleanTalk 6.1 -2026-03-25
CVE-2026-24750 Kiteworks Secure Data Forms vulnerable to Cross-site Scripting — Secure Data Forms 7.6 High2026-03-25
CVE-2026-3212 Tagify - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-013 — Tagify 6.1 -2026-03-25
CVE-2026-2349 UI Icons - Critical - Cross-site Scripting - SA-CONTRIB-2026-010 — UI Icons 6.1 -2026-03-25
CVE-2026-2348 Quick Edit - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-009 — Quick Edit 6.1 -2026-03-25
CVE-2026-4816 Reflected Cross Site Scripting (XSS) vulnerability in Support Board — Support Board 6.1 -2026-03-25
CVE-2025-40842 Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerability — Indoor Connect 8855 5.4 -2026-03-25

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21498 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.