Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21547

21547 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-28937 WordPress Lava Ajax Search plugin <= 1.1.9 - Cross Site Scripting (XSS) vulnerability — Lava Ajax Search 5.9 Medium2025-03-11
CVE-2025-28936 WordPress Lunar plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability — Lunar 5.9 Medium2025-03-11
CVE-2025-28930 WordPress List Mixcloud plugin <= 1.4 - Cross Site Scripting (XSS) vulnerability — List Mixcloud 6.5 Medium2025-03-11
CVE-2025-28929 WordPress Tabbed Login Widget plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability — Tabbed Login Widget 6.5 Medium2025-03-11
CVE-2025-28926 WordPress Post Read Time plugin <= 1.2.6 - Stored Cross Site Scripting (XSS) vulnerability — Post Read Time 5.9 Medium2025-03-11
CVE-2025-28919 WordPress Easy Image Display plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability — Easy Image Display 6.5 Medium2025-03-11
CVE-2025-28918 WordPress Featured Image Thumbnail Grid plugin <= 6.8 - Cross Site Scripting (XSS) vulnerability — Featured Image Thumbnail Grid 6.5 Medium2025-03-11
CVE-2025-28914 WordPress wordpress login form to anywhere plugin <= 0.2 - Cross Site Scripting (XSS) vulnerability — wordpress login form to anywhere 5.9 Medium2025-03-11
CVE-2025-28908 WordPress pipDisqus plugin <= 1.6 - Cross Site Scripting (XSS) vulnerability — pipDisqus 5.9 Medium2025-03-11
CVE-2025-28907 WordPress WP Last Modified plugin <= 0.1 - Cross Site Scripting (XSS) vulnerability — WP Last Modified 5.9 Medium2025-03-11
CVE-2025-28906 WordPress Skitter Slideshow plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerability — Skitter Slideshow 5.9 Medium2025-03-11
CVE-2025-28905 WordPress Featured Posts Grid plugin <= 1.7 - CSRF to Stored XSS vulnerability — Featured Posts Grid 7.1 High2025-03-11
CVE-2025-28895 WordPress Custom top bar plugin <= 2.1 - Cross Site Request Forgery (CSRF) vulnerability — Custom top bar 7.1 High2025-03-11
CVE-2025-28879 WordPress Bee Layer Slider plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability — Bee Layer Slider 6.5 Medium2025-03-11
CVE-2025-28878 WordPress Awesome Surveys plugin <= 2.0.10 - Cross Site Scripting (XSS) vulnerability — Awesome Surveys 5.9 Medium2025-03-11
CVE-2025-28875 WordPress BP Email Assign Templates By shanebp plugin <= 1.6 - Cross-Site Scripting vulnerability — BP Email Assign Templates 5.9 Medium2025-03-11
CVE-2025-28871 WordPress Block Spam By Math Reloaded plugin <= 2.2.4 - Cross Site Scripting (XSS) vulnerability — Block Spam By Math Reloaded 5.9 Medium2025-03-11
CVE-2025-28870 WordPress amoCRM WebForm plugin <= 1.1 - Cross Site Scripting (XSS) vulnerability — amoCRM WebForm 6.5 Medium2025-03-11
CVE-2025-2208 aitangbao springboot-manager Filename upload cross site scripting — springboot-manager 2.4 Low2025-03-11
CVE-2025-2207 aitangbao springboot-manager dept cross site scripting — springboot-manager 2.4 Low2025-03-11
CVE-2025-2206 aitangbao springboot-manager permission cross site scripting — springboot-manager 2.4 Low2025-03-11
CVE-2024-56338 IBM Sterling B2B Integrator cross-site scripting — Sterling B2B Integrator Standard Edition 4.8 Medium2025-03-11
CVE-2023-37933 Fortinet FortiADC 跨站脚本漏洞 — FortiADC 8.6 High2025-03-11
CVE-2025-2196 MRCMS org.marker.mushroom.controller.FileController upload.do upload cross site scripting — MRCMS 3.5 Low2025-03-11
CVE-2025-2195 MRCMS org.marker.mushroom.controller.FileController rename.do rename cross site scripting — MRCMS 3.5 Low2025-03-11
CVE-2025-2194 MRCMS org.marker.mushroom.controller.FileController list.do list cross site scripting — MRCMS 3.5 Low2025-03-11
CVE-2025-2191 Claro A7600-A1 Ping6 Diagnóstico form2pingv6.cgi cross site scripting — A7600-A1 2.4 Low2025-03-11
CVE-2025-1434 XSS in AREAL SAS Topkapi Vision Webserv2 — Topkapi Vision Webserv2 6.1 Medium2025-03-11
CVE-2024-13413 ProductDyno <= 1.0.24 - Reflected Cross-Site Scripting via 'res' Parameter — ProductDyno 6.1 Medium2025-03-11
CVE-2025-27434 Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI) — SAP Commerce (Swagger UI) 8.8 High2025-03-11

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21547 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.