Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21506

21506 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-41085 Stored Cross-Site Scripting (XSS) in Apidog web platform — Apidog Web Platform 5.4AIMediumAI2026-02-04
CVE-2026-0743 WP Content Permission <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ohmem-message' Parameter — WP Content Permission 4.4 Medium2026-02-04
CVE-2026-0742 Smart Appointment & Booking <= 1.0.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via saab_save_form_data AJAX Action — Smart Appointment & Booking 6.4 Medium2026-02-04
CVE-2026-0681 Extended Random Number Generator <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Settings — Extended Random Number Generator 4.4 Medium2026-02-04
CVE-2026-1819 Stored XSS in Karel Electronics' ViPort — ViPort 8.8 High2026-02-04
CVE-2026-22875 Movable Type 跨站脚本漏洞 — Movable Type (Software Edition) 4.8AIMediumAI2026-02-04
CVE-2026-21393 Movable Type 跨站脚本漏洞 — Movable Type (Software Edition) 5.4AIMediumAI2026-02-04
CVE-2026-1755 Menu Icons by ThemeIsle <= 0.13.20 - Authenticated (Author+) Stored Cross-Site Scripting — Menu Icons by ThemeIsle 6.4 Medium2026-02-03
CVE-2025-36033 IBM Engineering Lifecycle Management - Global Configuration Management is vulnerable to cross-site scripting — Engineering Lifecycle Management - Global Configuration Management 5.4 Medium2026-02-03
CVE-2020-37087 Easy Transfer 1.7 for iOS - Persistent Cross-Site Scripting — Easy Transfer 5.4AIMediumAI2026-02-03
CVE-2020-37072 Victor CMS 1.0 - 'comment_author' Persistent Cross-Site Scripting — CMSsite 7.2 High2026-02-03
CVE-2026-25148 Qwik SSR XSS via Unsafe Virtual Node Serialization — qwik 6.1AIMediumAI2026-02-03
CVE-2026-25616 Blesta 跨站脚本漏洞 — Blesta 4.7 Medium2026-02-03
CVE-2026-24426 Tenda AC7 Reflected XSS via Web Interface Output Encoding — Tenda AC7 6.1AIMediumAI2026-02-03
CVE-2026-25522 Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalation — commerce 4.8AIMediumAI2026-02-03
CVE-2026-25490 Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation — commerce 4.8AIMediumAI2026-02-03
CVE-2026-25489 Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalation — commerce 5.4AIMediumAI2026-02-03
CVE-2026-25488 Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalation — commerce 4.8AIMediumAI2026-02-03
CVE-2026-25487 Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation — commerce 4.8AIMediumAI2026-02-03
CVE-2026-25486 Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation — commerce 4.8AIMediumAI2026-02-03
CVE-2026-25485 Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege Escalation — commerce 4.8AIMediumAI2026-02-03
CVE-2026-25484 Craft Commerce has Stored XSS in Product Type Name — commerce 5.4AIMediumAI2026-02-03
CVE-2026-25483 Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration — commerce 5.4AIMediumAI2026-02-03
CVE-2026-25482 Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget) — commerce 5.4AIMediumAI2026-02-03
CVE-2026-24665 Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) via Student Assignment Upload — openeclass 8.7 High2026-02-03
CVE-2026-24674 Open eClass is Vulnerable to Reflected Cross-Site Scripting (XSS) in Multiple Endpoints — openeclass 4.7 Medium2026-02-03
CVE-2026-24672 Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) in User Profile Fields — openeclass 7.3 High2026-02-03
CVE-2026-24671 Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) in Multiple High-Privilege User Fields — openeclass 6.1 Medium2026-02-03
CVE-2020-37111 60CycleCMS 2.5.2 - 'news.php' Cross-site Scripting (XSS) Vulnerability — 60CycleCMS 6.1 Medium2026-02-03
CVE-2020-37103 DotNetNuke 9.5 - Persistent Cross-Site Scripting — DotNetNuke 6.4 Medium2026-02-03

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21506 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.