Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21500

21500 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-59542 Chamilo: Account Takeover via Stored XSS in Course Learning Paths — chamilo-lms 9.1 Critical2026-03-06
CVE-2025-55289 Chamilo: Stored Cross Site Scripting in Skills Argumentation — chamilo-lms 8.8 High2026-03-06
CVE-2026-3610 HSC Cybersecurity Mailinspector URL mliUserValidation.php cross site scripting — Mailinspector 4.3 Medium2026-03-06
CVE-2026-2593 Greenshift – animation and page builder blocks <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting — Greenshift – animation and page builder blocks 6.4 Medium2026-03-05
CVE-2025-55208 Chamilo LMS has Stored Cross Site Scripting on Social Networks Uploaded Files — chamilo-lms 9.1 Critical2026-03-05
CVE-2026-28436 Frappe: Stored XSS in avatar_macro.html — frappe 5.4 -2026-03-05
CVE-2026-28405 MarkUs: Stored XSS in Submission HTML Preview Enables Instructor-Context Actions — Markus 8.0 High2026-03-05
CVE-2026-28343 CKEditor: Cross-site scripting (XSS) in the HTML Support package — ckeditor5 6.4 Medium2026-03-05
CVE-2026-28222 Wagtail: Improper escaping of HTML (Cross-site Scripting) on TableBlock class attributes — wagtail 6.1 Medium2026-03-05
CVE-2026-28223 Wagtail: Improper escaping of HTML (Cross-site Scripting) in simple_translation admin interface — wagtail 6.1 Medium2026-03-05
CVE-2026-26276 Gogs: DOM-based XSS via milestone selection — gogs 7.3 High2026-03-05
CVE-2026-26195 Gogs: Stored XSS in branch and wiki views through author and committer names — gogs 5.4 -2026-03-05
CVE-2026-26022 Gogs: Stored XSS via data URI in issue comments — gogs 8.7 High2026-03-05
CVE-2026-28137 WordPress MediCenter - Health Medical Clinic WordPress Theme theme <= 14.9 - Reflected Cross Site Scripting (XSS) vulnerability — MediCenter - Health Medical Clinic 6.1 -2026-03-05
CVE-2026-28130 WordPress UDesign theme <= 4.14.0 - Reflected Cross Site Scripting (XSS) vulnerability — UDesign 6.1 -2026-03-05
CVE-2026-28127 WordPress Lawyer Directory plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability — Lawyer Directory 6.1 -2026-03-05
CVE-2026-28126 WordPress RH Frontend Publishing Pro plugin < 4.3.4 - Cross Site Scripting (XSS) vulnerability — RH Frontend Publishing Pro 6.1 -2026-03-05
CVE-2026-28122 WordPress ListingPro plugin <= 2.9.8 - Reflected Cross Site Scripting (XSS) vulnerability — ListingPro 6.1 -2026-03-05
CVE-2026-28112 WordPress AllInOne - Banner Rotator plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability — AllInOne - Banner Rotator 6.1 -2026-03-05
CVE-2026-28113 WordPress Ultimate Learning Pro plugin <= 3.9.1 - Reflected Cross Site Scripting (XSS) vulnerability — Ultimate Learning Pro 6.1 -2026-03-05
CVE-2026-28108 WordPress LambertGroup - AllInOne - Banner with Thumbnails plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability — LambertGroup - AllInOne - Banner with Thumbnails 6.1 -2026-03-05
CVE-2026-28110 WordPress LambertGroup - AllInOne - Banner with Playlist plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability — LambertGroup - AllInOne - Banner with Playlist 6.1 -2026-03-05
CVE-2026-28109 WordPress LambertGroup - AllInOne - Content Slider plugin <= 3.8 - Reflected Cross Site Scripting (XSS) vulnerability — LambertGroup - AllInOne - Content Slider 6.1 -2026-03-05
CVE-2026-28103 WordPress LBG Zoominoutslider plugin <= 5.4.5 - Reflected Cross Site Scripting (XSS) vulnerability — LBG Zoominoutslider 6.1 -2026-03-05
CVE-2026-28101 WordPress UberSlider MouseInteraction plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability — UberSlider MouseInteraction 6.1 -2026-03-05
CVE-2026-28100 WordPress UberSlider PerpetuumMobile plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability — UberSlider PerpetuumMobile 6.1 -2026-03-05
CVE-2026-28102 WordPress UberSlider Classic plugin <= 2.5 - Reflected Cross Site Scripting (XSS) vulnerability — UberSlider Classic 6.1 -2026-03-05
CVE-2026-28099 WordPress UberSlider Ultra plugin <= 2.3 - Reflected Cross Site Scripting (XSS) vulnerability — UberSlider Ultra 6.1 -2026-03-05
CVE-2026-28075 WordPress Porto theme <= 7.6.2 - Reflected Cross Site Scripting (XSS) vulnerability — Porto 6.1 -2026-03-05
CVE-2026-28072 WordPress pixfort Core plugin <= 3.2.22 - Reflected Cross Site Scripting (XSS) vulnerability — pixfort Core 6.1 -2026-03-05

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21500 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.