Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21536

21536 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-32167 WordPress SurveyJS plugin <= 1.12.20 - Cross Site Scripting (XSS) vulnerability — SurveyJS 6.5 Medium2025-04-04
CVE-2025-32166 WordPress Emma for WordPress plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability — Emma for WordPress 6.5 Medium2025-04-04
CVE-2025-32165 WordPress Doppler Forms plugin <= 2.5.1 - Cross Site Scripting (XSS) vulnerability — Doppler Forms 6.5 Medium2025-04-04
CVE-2025-32163 WordPress Xpro Elementor Addons plugin <= 1.4.10 - Cross Site Scripting (XSS) vulnerability — Xpro Elementor Addons 6.5 Medium2025-04-04
CVE-2025-32162 WordPress Chamber Dashboard Business Directory plugin <= 3.3.11 - Cross Site Scripting (XSS) vulnerability — Chamber Dashboard Business Directory 6.5 Medium2025-04-04
CVE-2025-32161 WordPress Arkhe Blocks plugin <= 2.27.1 - Cross Site Scripting (XSS) Vulnerability — Arkhe Blocks 6.5 Medium2025-04-04
CVE-2025-32136 WordPress ActiveCampaign Plugin <= 8.1.16 - Cross Site Scripting (XSS) vulnerability — ActiveCampaign 5.9 Medium2025-04-04
CVE-2025-32134 WordPress URL Shortify Plugin <= 1.10.5.1 - Cross Site Scripting (XSS) vulnerability — URL Shortify 5.9 Medium2025-04-04
CVE-2025-32135 WordPress Split Test For Elementor plugin <= 1.8.4 - Cross Site Scripting (XSS) vulnerability — Split Test For Elementor 5.9 Medium2025-04-04
CVE-2025-32133 WordPress Secure Copy Content Protection and Content Locking plugin <= 4.5.5 - Cross Site Scripting (XSS) vulnerability — Secure Copy Content Protection and Content Locking 5.9 Medium2025-04-04
CVE-2025-32132 WordPress FunnelCockpit Plugin <= 1.4.3 - Cross Site Scripting (XSS) vulnerability — FunnelCockpit 5.9 Medium2025-04-04
CVE-2025-32131 WordPress Social Intents plugin <= 1.6.19 - Cross Site Scripting (XSS) Vulnerability — Social Intents 5.9 Medium2025-04-04
CVE-2025-32130 WordPress Posts Footer Manager plugin <= 2.2.0 - Cross Site Scripting (XSS) Vulnerability — Posts Footer Manager 5.9 Medium2025-04-04
CVE-2025-32129 WordPress Welcome Bar plugin <= 2.0.4 - Cross Site Scripting (XSS) vulnerability — Welcome Bar 5.9 Medium2025-04-04
CVE-2025-3253 xujiangfei admintwo insertTree cross site scripting — admintwo 3.5 Low2025-04-04
CVE-2025-3252 xujiangfei admintwo add cross site scripting — admintwo 3.5 Low2025-04-04
CVE-2025-3251 xujiangfei admintwo updateSet cross site scripting — admintwo 3.5 Low2025-04-04
CVE-2025-22281 WordPress Simplish theme <= 2.6.4 - Stored Cross Site Scripting (XSS) vulnerability — Simplish 6.5 Medium2025-04-04
CVE-2025-31389 WordPress Sequel plugin <= 1.0.11 - Cross Site Scripting (XSS) vulnerability — Sequel 7.1 High2025-04-04
CVE-2025-31407 WordPress Tiger theme <= 2.0 - Cross Site Scripting (XSS) vulnerability — Tiger 6.5 Medium2025-04-04
CVE-2025-31416 WordPress Awesome Event Booking plugin <= 2.8.4 - Reflected Cross Site Scripting (XSS) vulnerability — Awesome Event Booking 7.1 High2025-04-04
CVE-2025-31418 WordPress Gravel theme <= 1.6 - Reflected Cross Site Scripting (XSS) vulnerability — Gravel 7.1 High2025-04-04
CVE-2025-22282 WordPress ez Form Calculator Premouium plugin <= 2.14.1.2 - Reflected Cross Site Scripting (XSS) vulnerability — ez Form Calculator Premium 7.1 High2025-04-04
CVE-2025-3219 CodeCanyon Perfex CRM Project Discussions Module 2 cross site scripting — Perfex CRM 3.5 Low2025-04-04
CVE-2025-3087 Stored XSS Vulnerability in M-Files Web — M-Files Web 5.4AIMediumAI2025-04-04
CVE-2025-2159 Stored XSS in M-Files Admin user interface — M-Files Admin 4.6AIMediumAI2025-04-04
CVE-2025-2836 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login 6.4 Medium2025-04-04
CVE-2024-13898 Simple Banner <= 3.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting — Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website 4.4 Medium2025-04-04
CVE-2025-3191 react-draft-wysiwyg 安全漏洞 — react-draft-wysiwyg 6.1 Medium2025-04-04
CVE-2025-25001 Microsoft Edge for iOS Spoofing Vulnerability — Microsoft Edge for iOS 4.3 Medium2025-04-04

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21536 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.