Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21551

21551 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-47437 WordPress WSB Brands Plugin <= 1.1.8 is vulnerable to Cross Site Scripting (XSS) — WSB Brands 5.9 Medium2023-05-08
CVE-2023-25052 WordPress Yandex.News Feed by Teplitsa Plugin <= 1.12.5 is vulnerable to Cross Site Scripting (XSS) — Yandex.News Feed by Teplitsa 5.9 Medium2023-05-08
CVE-2023-28169 WordPress Easy Event calendar Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) — Easy Event calendar 5.9 Medium2023-05-08
CVE-2023-25452 WordPress CMS Press Plugin <= 0.2.3 is vulnerable to Cross Site Scripting (XSS) — CMS Press 5.9 Medium2023-05-08
CVE-2022-45812 WordPress Exxp Plugin <= 2.6.8 is vulnerable to Cross Site Scripting (XSS) — Exxp 6.5 Medium2023-05-08
CVE-2023-23668 WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS) — GiveWP 6.5 Medium2023-05-08
CVE-2023-25021 WordPress FareHarbor for WordPress Plugin <= 3.6.6 is vulnerable to Cross Site Scripting (XSS) — FareHarbor for WordPress 5.9 Medium2023-05-08
CVE-2022-46799 WordPress Easy Testimonial Slider and Form Plugin <= 1.0.15 is vulnerable to Cross Site Scripting (XSS) — Easy Testimonial Slider and Form 7.1 High2023-05-08
CVE-2023-29247 Stored XSS on Apache Airflow — Apache Airflow 6.1 -2023-05-08
CVE-2023-2566 Cross-site Scripting (XSS) - Stored in openemr/openemr — openemr/openemr 5.4 -2023-05-08
CVE-2023-31183 Cybonet PineApp Mail Secure RXSS vulnerability — PineApp 6.1 Medium2023-05-08
CVE-2023-31180 WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - Reflected cross-site scripting (RXSS) — InnoKB Server, InnoKB/Console 6.1 Medium2023-05-08
CVE-2023-2565 SourceCodester Multi Language Hotel Management Software POST Parameter ajax.php cross site scripting — Multi Language Hotel Management Software 3.5 Low2023-05-07
CVE-2023-24400 WordPress Cookie Notice & Compliance for GDPR / CCPA Plugin <= 2.4.6 is vulnerable to Cross Site Scripting (XSS) — Cookie Notice & Compliance for GDPR / CCPA 6.5 Medium2023-05-06
CVE-2023-25491 WordPress JCH Optimize Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS) — JCH Optimize 5.9 Medium2023-05-06
CVE-2023-2560 jja8 NewBingGoGo cross site scripting — NewBingGoGo 3.5 Low2023-05-06
CVE-2023-26517 WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS) — Dashboard Widgets Suite 5.9 Medium2023-05-06
CVE-2023-26519 WordPress Publish to Schedule Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS) — Publish to Schedule 5.9 Medium2023-05-06
CVE-2023-24957 IBM Business Automation Workflow cross-site scripting — Business Automation Workflow 5.4 Medium2023-05-06
CVE-2022-43866 IBM Maximo Asset Management cross-site scripting — Maximo Asset Management 5.4 Medium2023-05-05
CVE-2017-20183 External Media without Import Plugin external-media-without-import.php print_media_new_panel cross site scripting — External Media without Import Plugin 3.5 Low2023-05-05
CVE-2023-2516 Cross-site Scripting (XSS) - Stored in nilsteampassnet/teampass — nilsteampassnet/teampass 5.4 -2023-05-05
CVE-2023-2427 Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq — thorsten/phpmyfaq 6.1 -2023-05-05
CVE-2023-2553 Cross-site Scripting (XSS) - Stored in unilogies/bumsys — unilogies/bumsys 5.4 -2023-05-05
CVE-2023-2550 Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq — thorsten/phpmyfaq 5.4 -2023-05-05
CVE-2022-47434 WordPress PB SEO Friendly Images Plugin <= 4.0.5 is vulnerable to Cross Site Scripting (XSS) — PB SEO Friendly Images 5.9 Medium2023-05-04
CVE-2022-47449 WordPress Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD Plugin <= 3.1.5 is vulnerable to Cross Site Scripting (XSS) — Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD 7.1 High2023-05-04
CVE-2023-25961 WordPress Darcie Theme <= 1.1.5 is vulnerable to Cross Site Scripting (XSS) — Darcie 7.1 High2023-05-04
CVE-2023-25982 WordPress Simple YouTube Responsive Plugin <= 2.5 is vulnerable to Cross Site Scripting (XSS) — Simple YouTube Responsive 6.5 Medium2023-05-04
CVE-2023-25977 WordPress CPT – Speakers Plugin <= 1.1 is vulnerable to Cross Site Scripting (XSS) — CPT – Speakers 5.9 Medium2023-05-04

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21551 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.