Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21551

21551 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-23928 WordPress Google Org Chart plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability — Google Org Chart 6.5 Medium2025-01-16
CVE-2025-23924 WordPress WP Photo Sphere plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability — WP Photo Sphere 6.5 Medium2025-01-16
CVE-2025-23935 WordPress Magic Google Maps plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability — Magic Google Maps 6.5 Medium2025-01-16
CVE-2025-23933 WordPress WpF Ultimate Carousel plugin <= 1.0.11 - Stored Cross Site Scripting (XSS) vulnerability — WpF Ultimate Carousel 6.5 Medium2025-01-16
CVE-2025-23925 WordPress Feedburner Optin Form plugin <= 0.2.8 - Stored Cross Site Scripting (XSS) vulnerability — Feedburner Optin Form 6.5 Medium2025-01-16
CVE-2025-23927 WordPress Incredible Font Awesome plugin <= 1.0 - Stored Cross Site Scripting (XSS) vulnerability — Incredible Font Awesome 6.5 Medium2025-01-16
CVE-2025-23936 WordPress CC Circle Progress Bar plugin <= 1.0.0 - Cross Site Scripting (XSS) vulnerability — CC Circle Progress Bar 6.5 Medium2025-01-16
CVE-2025-23926 WordPress Ajax WP Query Search Filter plugin <= 1.0.7 - Stored Cross Site Scripting (XSS) vulnerability — Ajax WP Query Search Filter 6.5 Medium2025-01-16
CVE-2025-23909 WordPress Compare Ninja plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerability — Compare Ninja 6.5 Medium2025-01-16
CVE-2025-23908 WordPress Pastebin plugin <= 1.5 - Cross Site Scripting (XSS) vulnerability — Pastebin 6.5 Medium2025-01-16
CVE-2025-23899 WordPress Bookalet plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability — Bookalet 6.5 Medium2025-01-16
CVE-2025-23897 WordPress Apply with LinkedIn buttons plugin <= 2.3 - Cross Site Scripting (XSS) vulnerability — Apply with LinkedIn buttons 6.5 Medium2025-01-16
CVE-2025-23887 WordPress Blog Summary plugin <= 0.1.2 β - Cross Site Scripting (XSS) vulnerability — Blog Summary 6.5 Medium2025-01-16
CVE-2025-23891 WordPress Yet Another Countdown Plugin plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability — Yet Another Countdown 6.5 Medium2025-01-16
CVE-2025-23892 WordPress Progress Tracker plugin <= 0.9.3 - Cross Site Scripting (XSS) vulnerability — Progress Tracker 6.5 Medium2025-01-16
CVE-2025-23896 WordPress Mindmeister Shortcode plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability — Mindmeister Shortcode 6.5 Medium2025-01-16
CVE-2025-23890 WordPress Easy Tweet Embed plugin <= 1.7 - Cross Site Scripting (XSS) vulnerability — Easy Tweet Embed 6.5 Medium2025-01-16
CVE-2025-23893 WordPress GMap Shortcode plugin <= 2.0 - Cross Site Scripting (XSS) vulnerability — GMap Shortcode 6.5 Medium2025-01-16
CVE-2025-23876 WordPress WP krpano plugin <= 1.2.1 - Stored Cross Site Scripting (XSS) vulnerability — WP krpano 6.5 Medium2025-01-16
CVE-2025-23886 WordPress Annie plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability — Annie 6.5 Medium2025-01-16
CVE-2025-23878 WordPress Post-to-Post Links plugin <= 4.2 - Cross Site Scripting (XSS) vulnerability — Post-to-Post Links 5.9 Medium2025-01-16
CVE-2025-23877 WordPress Nite Shortcodes plugin <= 1.0 - Stored Cross Site Scripting (XSS) vulnerability — Nite Shortcodes 6.5 Medium2025-01-16
CVE-2025-23873 WordPress Category D3 Tree plugin <= 1.1 - Stored Cross Site Scripting (XSS) vulnerability — Category D3 Tree 6.5 Medium2025-01-16
CVE-2025-23864 WordPress WCS QR Code Generator plugin <= 1.0 - Stored Cross Site Scripting (XSS) vulnerability — WCS QR Code Generator 6.5 Medium2025-01-16
CVE-2025-23868 WordPress Chess Tempo Viewer plugin <= 0.9.5 - Stored Cross Site Scripting (XSS) vulnerability — Chess Tempo Viewer 6.5 Medium2025-01-16
CVE-2025-23865 WordPress Winning Portfolio plugin <= 1.1 - Stored Cross Site Scripting (XSS) vulnerability — Winning Portfolio 6.5 Medium2025-01-16
CVE-2025-23863 WordPress Rollover Tab plugin <= 1.3.2 - Stored Cross Site Scripting (XSS) vulnerability — Rollover Tab 6.5 Medium2025-01-16
CVE-2025-23854 WordPress Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com plugin <= 3.3 - Cross Site Scripting (XSS) vulnerability — Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com 5.9 Medium2025-01-16
CVE-2025-23859 WordPress Daily Proverb plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability — Daily Proverb 6.5 Medium2025-01-16
CVE-2025-23860 WordPress Charity-thermometer plugin <= 1.1.2 - Cross Site Scripting (XSS) vulnerability — Charity-thermometer 6.5 Medium2025-01-16

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21551 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.