Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21517

21517 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-67475 Stored XSS through edit summaries in MW Core — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-67477 Stored XSS through a system message in Special:ApiSandbox — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-61655 Stored XSS through system messages in VisualEditor — VisualEditor 6.1AIMediumAI2026-02-03
CVE-2025-61656 XSS when pasting into VE — VisualEditor 6.1AIMediumAI2026-02-03
CVE-2025-61657 Wikimedia Vector 安全漏洞 — Vector 6.1AIMediumAI2026-02-03
CVE-2025-61651 i18n XSS through Special:CheckUser CheckUser helper — CheckUser 6.1AIMediumAI2026-02-03
CVE-2025-11261 Stored i18n XSS exposed by security patch for T402077 — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-61648 Stored XSS through system messages in CheckUser — CheckUser 6.1AIMediumAI2026-02-03
CVE-2025-61650 UserInfoCard is vulnerable to message key stored XSS — CheckUser 6.1AIMediumAI2026-02-03
CVE-2025-61645 CodexTablePager has i18n XSS — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-61644 i18n XSS through Special:Watchlist — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61637 Stored XSS through system messages in MW Core — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61638 Sanitizer::validateAttributes data-XSS — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61640 Stored XSS through system messages in Special:RecentChangesLinked (MW Core) — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61642 Stored XSS through system messages provided to CodexHtmlForms — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61636 Codex Special:Block vulnerable to message key XSS — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-6594 XSS in Special:ApiSandbox — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-6595 MediaWiki 安全漏洞 — MultimediaViewer 6.1AIMediumAI2026-02-02
CVE-2025-6596 Vector inserts portlet labels as HTML, allowing for stored XSS through system messages — Vector 6.1AIMediumAI2026-02-02
CVE-2026-25144 Talishar has a Stored XSS which can lead to data exfiltration & user impersonation — Talishar 5.3 Medium2026-02-02
CVE-2025-36436 Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for January 2026. — Cloud Pak for Business Automation 6.4 Medium2026-02-02
CVE-2026-23476 FacturaScripts Affected by Reflected XSS — facturascripts 5.4 Medium2026-02-02
CVE-2026-23997 FacturaScripts has a Stored Cross-Site Scripting (XSS) in "Observations" field via History View — facturascripts 8.0 High2026-02-02
CVE-2026-22881 Cybozu Garoon 跨站脚本漏洞 — Cybozu Garoon 6.1AIMediumAI2026-02-02
CVE-2026-20711 Cybozu Garoon 跨站脚本漏洞 — Cybozu Garoon 6.1AIMediumAI2026-02-02
CVE-2026-1744 D-Link DSL-6641K sp_pppoe_user.js doSubmitPPP cross site scripting — DSL-6641K 2.4 Low2026-02-02
CVE-2023-54343 QWE DL 2.0.1 Persistent XSS Vulnerability via Path Parameter — QWE DL 6.4 Medium2026-02-01
CVE-2022-50952 Banco Guayaquil 8.0.0 Mobile iOS Cross-Site Scripting via Profile Name Input — Banco Guayaquil 6.4 Medium2026-02-01
CVE-2022-50951 WiFi File Transfer 1.0.8 Persistent XSS via Web Server Input Validation — WiFi File Transfer 6.4 Medium2026-02-01
CVE-2022-50941 BootCommerce 3.2.1 Persistent Cross-Site Scripting via Order Checkout — BootCommerce 6.4 Medium2026-02-01

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21517 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.