Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21501

21501 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-3041 xingfuggz BaykeShop Article Sidebar custom.html cross site scripting — BaykeShop 2.4 Low2026-02-23
CVE-2026-27742 Bludit <= 3.16.2 Stored XSS in Post Content — Bludit 5.4 Medium2026-02-23
CVE-2026-3028 erzhongxmu JEEWMS JeecgListDemoController.java doAdd cross site scripting — JEEWMS 4.3 Medium2026-02-23
CVE-2026-3027 erzhongxmu JEEWMS UEditor getContent.jsp cross site scripting — JEEWMS 4.3 Medium2026-02-23
CVE-2026-25648 Traccar Vulnerable to Stored Cross-Site Scripting (XSS) via Malicious SVG File Upload — traccar 8.7 High2026-02-23
CVE-2026-27512 Tenda F3 Reflected Script Execution via Missing nosniff Header — Tenda F3 6.1 Medium2026-02-23
CVE-2025-40986 Reflected Cross-Site Scripting in PideTuCita — PideTuCita 6.1AIMediumAI2026-02-23
CVE-2025-40701 Reflected Cross-Site scripting (XSS) in SOTE's SOTESHOP — SOTESHOP 6.1AIMediumAI2026-02-23
CVE-2026-2972 a466350665 Smart-SSO Role Edit UserController.java save cross site scripting — Smart-SSO 2.4 Low2026-02-23
CVE-2026-2971 a466350665 Smart-SSO Login login.html cross site scripting — Smart-SSO 4.3 Medium2026-02-23
CVE-2026-2965 07FLYCMS/07FLY-CMS/07FlyCRM System Extension edit.html cross site scripting — 07FLYCMS 2.4 Low2026-02-23
CVE-2026-2947 rymcu forest User Profile UserInfoController.java updateUserInfo cross site scripting — forest 3.5 Low2026-02-22
CVE-2026-2946 rymcu forest Article Content/Comments/Portfolio XssUtils.java XssUtils.replaceHtmlCode cross site scripting — forest 3.5 Low2026-02-22
CVE-2026-2943 SapneshNaik Student Management System index.php cross site scripting — Student Management System 4.3 Medium2026-02-22
CVE-2026-2939 itsourcecode Student Management System Add Student add_student cross site scripting — Student Management System 2.4 Low2026-02-22
CVE-2026-2934 YiFang CMS Extended Management D_friendLinkGroup.php update cross site scripting — CMS 2.4 Low2026-02-22
CVE-2026-2933 YiFang CMS Extended Management D_adManage.php update cross site scripting — CMS 2.4 Low2026-02-22
CVE-2026-2932 YiFang CMS Extended Management D_adPosition.php update cross site scripting — CMS 2.4 Low2026-02-22
CVE-2026-2897 funadmin Backend index.html cross site scripting — funadmin 2.4 Low2026-02-22
CVE-2026-27469 Isso: Stored XSS via comment website field — isso 6.1 Medium2026-02-21
CVE-2026-27210 Pannellum has a XSS vulnerability in hot spot attributes — pannellum 6.1AIMediumAI2026-02-21
CVE-2026-27196 Statamic affected by privilege escalation via stored Cross-site Scripting — cms 8.1 High2026-02-21
CVE-2026-27169 OpenSift: Persistent XSS Chat Tool Rendering — OpenSift 8.9 High2026-02-20
CVE-2026-27147 GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated) — GetSimpleCMS-CE 5.4AIMediumAI2026-02-20
CVE-2019-25454 phpMoAdmin 1.1.5 Stored Cross-Site Scripting via collection Parameter — phpMoAdmin 6.1 Medium2026-02-20
CVE-2019-25453 phpMoAdmin 1.1.5 Reflected Cross-Site Scripting via moadmin.php — phpMoAdmin 6.1 Medium2026-02-20
CVE-2019-25449 OrientDB 3.0.17 Reflected Cross-Site Scripting via document endpoint — OrientDB 6.1 Medium2026-02-20
CVE-2019-25448 OrientDB 3.0.17 Stored Cross-Site Scripting via User Creation — OrientDB 6.4 Medium2026-02-20
CVE-2026-27122 Svelte SSR does not validate dynamic element tag names in `<svelte:element>` — svelte 6.1 -2026-02-20
CVE-2026-27121 Svelte affected by cross-site scripting via spread attributes in Svelte SSR — svelte 6.1 -2026-02-20

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21501 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.