Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21551

21551 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-27351 WordPress Local Search SEO Contact Page plugin <= 4.0.1 - Cross Site Scripting (XSS) vulnerability — Local Search SEO Contact Page 6.5 Medium2025-02-24
CVE-2025-27349 WordPress Get Posts plugin <= 0.6 - Stored Cross Site Scripting (XSS) vulnerability — Get Posts 6.5 Medium2025-02-24
CVE-2025-27348 WordPress WP Social SEO Booster plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability — WP Social SEO Booster – Knowledge Graph Social Signals SEO 6.5 Medium2025-02-24
CVE-2025-27347 WordPress Direct Checkout Button for WooCommerce plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability — Direct Checkout Button for WooCommerce 6.5 Medium2025-02-24
CVE-2025-27341 WordPress Reactive Mortgage Calculator plugin <= 1.1 - Stored Cross Site Scripting (XSS) vulnerability — Reactive Mortgage Calculator 6.5 Medium2025-02-24
CVE-2025-27331 WordPress WooCommerce Display Products by Tags plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability — WooCommerce Display Products by Tags 6.5 Medium2025-02-24
CVE-2025-27330 WordPress PlayerJS plugin <= 2.23 - Cross Site Scripting (XSS) vulnerability — PlayerJS 6.5 Medium2025-02-24
CVE-2025-27329 WordPress EZ InLinkz linkup plugin <= 0.18 - Cross Site Scripting (XSS) vulnerability — EZ InLinkz linkup 6.5 Medium2025-02-24
CVE-2025-27327 WordPress Live Streaming Video Player – by SRS Player plugin <= 1.0.18 - Cross Site Scripting (XSS) vulnerability — Live Streaming Video Player – by SRS Player 6.5 Medium2025-02-24
CVE-2025-27325 WordPress Video.js HLS Player plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability — Video.js HLS Player 6.5 Medium2025-02-24
CVE-2025-27323 WordPress WP About Author plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability — WP About Author 6.5 Medium2025-02-24
CVE-2025-27320 WordPress Profile Widget Ninja plugin <= 4.3 - Cross Site Scripting (XSS) vulnerability — Profile Widget Ninja 6.5 Medium2025-02-24
CVE-2025-27307 WordPress Quotes llama plugin <= 3.0.1 - Stored Cross Site Scripting (XSS) vulnerability — Quotes llama 6.5 Medium2025-02-24
CVE-2025-27305 WordPress Table of Contents Block plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability — Table of Contents Block 6.5 Medium2025-02-24
CVE-2025-27306 WordPress Pathomation plugin <= 2.5.1 - Stored Cross Site Scripting (XSS) vulnerability — Pathomation 6.5 Medium2025-02-24
CVE-2025-27304 WordPress Contact Form 7 Star Rating with font Awesome plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability — Contact Form 7 Star Rating with font Awesome 5.9 Medium2025-02-24
CVE-2025-27303 WordPress Contact Form 7 Star Rating plugin <= 1.10 - Cross Site Scripting (XSS) vulnerability — Contact Form 7 Star Rating 5.9 Medium2025-02-24
CVE-2025-27280 WordPress Archive Page plugin <= 1.0.2 - Cross Site Scripting (XSS) vulnerability — Archive Page 6.5 Medium2025-02-24
CVE-2025-27266 WordPress Hover Image Button plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability — Hover Image Button 6.5 Medium2025-02-24
CVE-2025-27265 WordPress Google Maps for WordPress plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability — Google Maps for WordPress 6.5 Medium2025-02-24
CVE-2025-0545 XSS in Tekrom Technology's T-Soft E-Commerce — T-Soft E-Commerce 4.7 Medium2025-02-24
CVE-2025-1618 vTiger CRM index.php cross site scripting — CRM 4.3 Medium2025-02-24
CVE-2025-1617 Netis WF2780 Wireless 2.4G Menu cross site scripting — WF2780 2.4 Low2025-02-24
CVE-2025-1615 FiberHome AN5506-01A ONU GPON NAT Submenu cross site scripting — AN5506-01A ONU GPON 2.4 Low2025-02-24
CVE-2025-1614 FiberHome AN5506-01A ONU GPON Port Forwarding Submenu portForwardingCfg cross site scripting — AN5506-01A ONU GPON 2.4 Low2025-02-24
CVE-2025-1613 FiberHome AN5506-01A ONU GPON URL Filtering Submenu URL_filterCfg cross site scripting — AN5506-01A ONU GPON 2.4 Low2025-02-24
CVE-2025-1612 Edimax BR-6288ACL wireless5g_basic.asp cross site scripting — BR-6288ACL 3.5 Low2025-02-24
CVE-2025-1597 SourceCodester Best Church Management Software redirect.php cross site scripting — Best Church Management Software 3.5 Low2025-02-23
CVE-2025-22635 WordPress Eventer - WordPress Event & Booking Manager Plugin plugin < 3.9.9 - Reflected Cross Site Scripting (XSS) vulnerability — Eventer 7.1 High2025-02-23
CVE-2025-22632 WordPress WooCommerce Pricing – Product Pricing plugin <= 1.0.9 - Cross Site Scripting (XSS) vulnerability — WooCommerce Pricing – Product Pricing 7.1 High2025-02-23

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21551 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.