Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21551

21551 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-24541 WordPress DK White Label plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability — DK White Label 7.1 High2025-02-03
CVE-2025-24536 WordPress ThriveDesk plugin <= 2.0.6 - Reflected Cross Site Scripting (XSS) vulnerability — ThriveDesk 7.1 High2025-02-03
CVE-2025-24544 WordPress Bitcoin and Altcoin Wallets plugin <= 6.3.1 - Reflected Cross Site Scripting (XSS) vulnerability — Bitcoin and Altcoin Wallets 7.1 High2025-02-03
CVE-2025-23923 WordPress Lockets Plugin <= 0.999 - Reflected Cross Site Scripting (XSS) vulnerability — Lockets 7.1 High2025-02-03
CVE-2025-23755 WordPress PAFacile plugin <= 2.6.1 - Reflected Cross Site Scripting (XSS) vulnerability — PAFacile 7.1 High2025-02-03
CVE-2025-23747 WordPress Awesome Timeline plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability — Awesome Timeline 6.5 Medium2025-02-03
CVE-2025-23920 WordPress ApplicantPro Plugin <= 1.3.9 - Reflected Cross Site Scripting (XSS) vulnerability — ApplicantPro 7.1 High2025-02-03
CVE-2025-23799 WordPress .TUBE Video Curator Plugin <= 1.1.9 - Reflected Cross Site Scripting (XSS) vulnerability — .TUBE Video Curator 7.1 High2025-02-03
CVE-2025-23685 WordPress RomanCart On WordPress plugin <= 0.0.2 - Reflected Cross Site Scripting (XSS) vulnerability — RomanCart 7.1 High2025-02-03
CVE-2025-23614 WordPress WordPress Additional Logins plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability — WordPress Additional Logins 7.1 High2025-02-03
CVE-2025-23594 WordPress Google Map With Fancybox plugin <= 2.1.0 - Reflected Cross Site Scripting (XSS) vulnerability — Google Map With Fancybox 7.1 High2025-02-03
CVE-2025-23599 WordPress eMarksheet plugin <= 5.0 - Reflected Cross Site Scripting (XSS) vulnerability — eMarksheet 7.1 High2025-02-03
CVE-2025-23590 WordPress Dezdy plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability — Dezdy 7.1 High2025-02-03
CVE-2025-23582 WordPress Bulk Categories Assign plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability — Bulk Categories Assign 7.1 High2025-02-03
CVE-2025-23591 WordPress blu Logistics plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability — blu Logistics 7.1 High2025-02-03
CVE-2025-23593 WordPress EmailPress plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability — EmailPress 7.1 High2025-02-03
CVE-2025-23588 WordPress WOW Best CSS Compiler plugin <= 2.0.2 - Reflected Cross Site Scripting (XSS) vulnerability — WOW Best CSS Compiler 7.1 High2025-02-03
CVE-2025-24781 WordPress WPJobBoard plugin <= 5.10.1 - Reflected Cross Site Scripting (XSS) vulnerability — WPJobBoard 7.1 High2025-02-03
CVE-2025-23561 WordPress MLL Audio Player MP3 Ajax plugin <= 0.7 - Cross Site Scripting (XSS) vulnerability — MLL Audio Player MP3 Ajax 6.5 Medium2025-02-03
CVE-2025-23491 WordPress VSTEMPLATE Creator plugin <= 2.0.2 - Reflected Cross Site Scripting (XSS) vulnerability — VSTEMPLATE Creator 7.1 High2025-02-03
CVE-2025-23581 WordPress Demo User DZS plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability — Demo User DZS 6.5 Medium2025-02-03
CVE-2025-0972 Zenvia Movidesk New Ticket cross site scripting — Movidesk 3.5 Low2025-02-03
CVE-2025-25062 Backdrop CMS 安全漏洞 — backdrop 4.4 Medium2025-02-03
CVE-2025-25063 Backdrop CMS 安全漏洞 — backdrop 4.4 Medium2025-02-03
CVE-2025-0971 Zenvia Movidesk Profile Editing EditProfile cross site scripting — Movidesk 3.5 Low2025-02-02
CVE-2025-0961 code-projects Job Recruitment load_job-details.php cross site scripting — Job Recruitment 3.5 Low2025-02-01
CVE-2024-13612 Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages 6.4 Medium2025-02-01
CVE-2024-11829 The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce 6.4 Medium2025-02-01
CVE-2024-11780 Site Search 360 <= 2.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting — Site Search 360 6.4 Medium2025-02-01
CVE-2024-13547 aThemes Addons for Elementor <= 1.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting — aThemes Addons for Elementor 6.4 Medium2025-02-01

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21551 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.