Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21535

21535 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-2161 Pegasystem Pega Platform 安全漏洞 — Pega Infinity 7.1 High2025-04-14
CVE-2025-2160 Pegasystem Pega Platform 安全漏洞 — Pega Infinity 8.1 High2025-04-14
CVE-2025-3568 Webkul Krayin CRM SVG File edit cross site scripting — Krayin CRM 3.5 Low2025-04-14
CVE-2024-49708 XSS in iKSORIS — iKSORIS 5.4AIMediumAI2025-04-14
CVE-2024-49707 XSS in iKSORIS — iKSORIS 6.1AIMediumAI2025-04-14
CVE-2024-13598 XSS in iKSORIS — iKSORIS 6.1AIMediumAI2025-04-14
CVE-2024-13597 XSS in iKSORIS — iKSORIS 6.1AIMediumAI2025-04-14
CVE-2024-10090 XSS in iKSORIS — iKSORIS 6.1AIMediumAI2025-04-14
CVE-2024-10089 XSS in iKSORIS — iKSORIS 5.4AIMediumAI2025-04-14
CVE-2024-10088 XSS in iKSORIS — iKSORIS 6.1AIMediumAI2025-04-14
CVE-2024-10087 XSS in iKSORIS — iKSORIS 6.1AIMediumAI2025-04-14
CVE-2025-3560 ghostxbh uzy-ssm-mall product cross site scripting — uzy-ssm-mall 3.5 Low2025-04-14
CVE-2025-3554 phpshe api.php cross site scripting — phpshe 4.3 Medium2025-04-14
CVE-2025-3423 IBM Aspera Faspex 5 cross-site scripting — Aspera Faspex 5.4 Medium2025-04-13
CVE-2025-3533 YouDianCMS index.html.Attackers cross site scripting — YouDianCMS 4.3 Medium2025-04-13
CVE-2025-3532 YouDianCMS index.html.Attackers cross site scripting — YouDianCMS 4.3 Medium2025-04-13
CVE-2025-3531 YouDianCMS index.html cross site scripting — YouDianCMS 4.3 Medium2025-04-13
CVE-2025-1456 Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated DOM-Based (Contributor+) Stored Cross-Site Scripting — Royal Addons for Elementor – Addons and Templates Kit for Elementor 6.4 Medium2025-04-12
CVE-2025-1455 Royal Elementor Addons and Templates <= 1.7.1012 - Authenticated (Contributor+) Stored Cross-Site Scripting — Royal Addons for Elementor – Addons and Templates Kit for Elementor 6.4 Medium2025-04-12
CVE-2025-3276 SKT Blocks – Gutenberg based Page Builder <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting — SKT Blocks – Gutenberg based Page Builder 6.4 Medium2025-04-12
CVE-2025-2269 Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.34 Reflected Cross-Site Scripting via 'image_id' Parameter — Photo Gallery by 10Web – Mobile-Friendly Image Gallery 6.1 Medium2025-04-11
CVE-2025-32426 Formie has a XSS vulnerability for email notification content for preview — formie 4.6 Medium2025-04-11
CVE-2025-32427 Formie has a XSS vulnerability for importing forms — formie 7.2AIHighAI2025-04-11
CVE-2025-3421 Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting — Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder 6.1 Medium2025-04-11
CVE-2025-2575 Z Companion <= 1.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload — Z Companion 6.4 Medium2025-04-11
CVE-2025-2541 WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload — Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker 6.4 Medium2025-04-11
CVE-2025-32632 WordPress Automatic Ban IP Plugin <= 1.0.7 - Reflected Cross Site Scripting (XSS) vulnerability — Automatic Ban IP 7.1 High2025-04-11
CVE-2025-32600 WordPress Tournamatch plugin <= 4.7.0 - Cross Site Scripting (XSS) vulnerability — Tournamatch 7.1 High2025-04-11
CVE-2025-32599 WordPress Task Scheduler Plugin <= 1.6.3 - Reflected Cross Site Scripting (XSS) vulnerability — Task Scheduler 7.1 High2025-04-11
CVE-2025-32601 WordPress Twispay Credit Card Payments Plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerability — Twispay Credit Card Payments 7.1 High2025-04-11

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21535 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.