Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21506

21506 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2019-25265 Online Inventory Manager 3.2 - Persistent Cross-Site Scripting — Online Inventory Manager 6.4 Medium2026-02-03
CVE-2019-25263 Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting — Zendesk App SweetHawk Survey 6.4 Medium2026-02-03
CVE-2019-25264 Snipe-IT Open Source Asset Management 4.7.5 - Persistent Cross-Site Scripting — IT Open Source Asset Management 6.4 Medium2026-02-03
CVE-2026-23794 Apache Syncope: Reflected XSS on Enduser Login — Apache Syncope 6.1AIMediumAI2026-02-03
CVE-2026-24988 WordPress The Events Calendar Shortcode & Block plugin <= 3.1.1 - Cross Site Scripting (XSS) vulnerability — The Events Calendar Shortcode &amp; Block 5.4AIMediumAI2026-02-03
CVE-2026-24958 WordPress JetElements For Elementor plugin <= 2.7.12.2 - Cross Site Scripting (XSS) vulnerability — JetElements For Elementor 6.1AIMediumAI2026-02-03
CVE-2026-24952 WordPress Seriously Simple Podcasting plugin <= 3.14.1 - Cross Site Scripting (XSS) vulnerability — Seriously Simple Podcasting 5.4AIMediumAI2026-02-03
CVE-2026-24938 WordPress Better Search plugin <= 4.2.1 - Cross Site Scripting (XSS) vulnerability — Better Search 5.4AIMediumAI2026-02-03
CVE-2025-7760 Reflected XSS in Ofisimo's Association Web Package Flora — Association Web Package Flora 7.6 High2026-02-03
CVE-2025-6397 XSS in Ankara Hosting's web site — Website Software 8.6 High2026-02-03
CVE-2025-67855 Mooodle: mooodle: information disclosure and script execution via reflected cross-site scripting 5.4 Medium2026-02-03
CVE-2025-67850 Moodle: moodle: cross-site scripting vulnerability via inadequate input filtering in formula editor 7.3 High2026-02-03
CVE-2025-67849 Moodle: moodle: cross-site scripting (xss) via improper sanitization of ai prompt responses 7.3 High2026-02-03
CVE-2025-59902 HTML injection in NICE Chat — NICE Chat 6.1AIMediumAI2026-02-03
CVE-2025-41065 Stored Cross-Site Scripting (XSS) in LUNA from Luna Imaging — LUNA 5.4AIMediumAI2026-02-03
CVE-2025-8461 Reflected XSS in Seres Software's syWEB — syWEB 7.6 High2026-02-03
CVE-2025-8456 Reflected XSS in Kod8 Software's Kod8 Individual and SME Website — Kod8 Individual and SME Website 7.6 High2026-02-03
CVE-2026-1592 Stored XSS via Create New Layer Field found in Foxit PDF Editor Cloud — pdfonline.foxit.com 6.3 Medium2026-02-03
CVE-2026-1591 Stored XSS via Attachments Feature in https://pdfonline.foxit.com/ — pdfonline.foxit.com 6.3 Medium2026-02-03
CVE-2025-8589 Reflected XSS in AKCE Software's SKSPro — SKSPro 7.6 High2026-02-03
CVE-2026-1058 Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder 7.1 High2026-02-03
CVE-2026-1210 Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field — Happy Addons for Elementor 6.4 Medium2026-02-03
CVE-2026-0617 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting — LatePoint – Calendar Booking Plugin for Appointments and Events 7.2 High2026-02-03
CVE-2025-14274 Unlimited Elements for Elementor <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget — Unlimited Elements For Elementor 5.4 Medium2026-02-03
CVE-2025-67481 mw.message(…).parse() doesn't output safe HTML, but it's being used as if it does — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-67483 Theoretical i18n XSS in mediawiki.page.preview.js when a page has multiple protection levels — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-67475 Stored XSS through edit summaries in MW Core — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-67477 Stored XSS through a system message in Special:ApiSandbox — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-61655 Stored XSS through system messages in VisualEditor — VisualEditor 6.1AIMediumAI2026-02-03
CVE-2025-61656 XSS when pasting into VE — VisualEditor 6.1AIMediumAI2026-02-03

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21506 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.