Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21534

21534 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-37342 WordPress Add Shortcodes Actions And Filters plugin <= 2.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — Add Shortcodes Actions And Filters (WordPress plugin) 4.8 Medium2022-09-23
CVE-2022-40193 WordPress Awesome Filterable Portfolio plugin <= 1.9.7 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability — Awesome Filterable Portfolio (WordPress plugin) 6.1 Medium2022-09-23
CVE-2022-38460 WordPress NOTICE BOARD plugin <= 1.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — NOTICE BOARD (WordPress plugin) 5.4 Medium2022-09-23
CVE-2022-37328 WordPress History Timeline plugin <= 1.0.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — History Timeline (WordPress plugin) 3.4 Low2022-09-23
CVE-2022-36791 WordPress Torro Forms plugin <= 1.0.16 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — Torro Forms (WordPress plugin) 5.4 Medium2022-09-23
CVE-2022-3144 Wordfence Security – Firewall & Malware Scan <= 7.6.0 - Authenticated (Admin+) Stored Cross-Site Scripting — Wordfence Security – Firewall, Malware Scan, and Login Security 4.4 Medium2022-09-23
CVE-2022-2937 Image Hover Effects Ultimate <= 9.7.3 - Authenticated Stored Cross-Site Scripting via Title & Description — Image Hover Effects Ultimate 6.4 Medium2022-09-23
CVE-2022-38703 WordPress Button Plugin MaxButtons plugin <= 9.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — WordPress Button Plugin MaxButtons (WordPress plugin) 3.4 Low2022-09-23
CVE-2022-40213 WordPress GS Testimonial Slider plugin <= 1.9.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities — GS Testimonial Slider (WordPress plugin) 4.1 Medium2022-09-23
CVE-2022-37339 WordPress Meet My Team plugin <= 2.0.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — Meet My Team (WordPress plugin) 4.1 Medium2022-09-23
CVE-2022-37338 WordPress Blossom Recipe Maker plugin <= 1.0.7 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities — Blossom Recipe Maker (WordPress plugin) 4.1 Medium2022-09-23
CVE-2022-37330 WordPress WHA Crossword plugin <= 1.1.10 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — WHA Crossword (WordPress plugin) 5.4 Medium2022-09-23
CVE-2022-39239 nefly-ipx subject to Server-Side Request Forgery and Stored Cross-Site Scripting via Cache Poisoning and Improper Host Validation — netlify-ipx 6.1 Medium2022-09-23
CVE-2022-23458 Toast UI Grid vulnerable to Cross-site scripting — tui.grid 6.1 Medium2022-09-22
CVE-2022-2266 Reflected XSS University Library Automation System — Yordam Bilgi Teknolojileri 6.1 Medium2022-09-22
CVE-2022-38073 WordPress Awesome Support plugin <= 6.0.7 - Multiple Authenticated Persistent XSS (Additional Interested Parties) — Awesome Support (WordPress plugin) 5.4 Medium2022-09-21
CVE-2022-36365 WordPress WHA Crossword plugin <= 1.1.10 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities — WHA Crossword (WordPress plugin) 5.4 Medium2022-09-21
CVE-2022-36383 WordPress Word Search Puzzles game plugin <= 2.0.1 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities — Word Search Puzzles game (WordPress plugin) 5.4 Medium2022-09-21
CVE-2022-36390 WordPress Event Calendar – Calendar plugin <= 1.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability — Event Calendar – Calendar (WordPress plugin) 4.1 Medium2022-09-21
CVE-2022-3255 Cross-site Scripting (XSS) - Reflected in pimcore/pimcore — pimcore/pimcore 3.5 -2022-09-21
CVE-2022-39220 XSS Vulnerabilities in WebClient — sftpgo 6.1 Medium2022-09-20
CVE-2022-32167 Cloudreve - Stored XSS — Cloudreve 5.4 Medium2022-09-20
CVE-2022-3005 Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm — yetiforcecompany/yetiforcecrm 5.4 -2022-09-20
CVE-2022-3004 Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm — yetiforcecompany/yetiforcecrm 5.4 -2022-09-20
CVE-2022-3000 Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm — yetiforcecompany/yetiforcecrm 5.4 -2022-09-20
CVE-2022-2924 Cross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrm — yetiforcecompany/yetiforcecrm 5.4 -2022-09-20
CVE-2022-3021 Slickr Flickr <= 2.8.1 - Admin+ Stored Cross-Site Scripting — Slickr Flickr 4.8 -2022-09-19
CVE-2022-3036 Gettext override translations < 2.0.0 - Admin+ Stored Cross-Site Scripting — Gettext override translations 4.8 -2022-09-19
CVE-2022-2753 Ketchup Restaurant Reservations <= 1.0.0 - Unauthenticated Stored XSS — Ketchup Restaurant Reservations 6.1 -2022-09-19
CVE-2022-2710 Scroll To Top < 1.4.1 - Admin+ Stored Cross-Site Scripting — Scroll To Top 4.8 -2022-09-19

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21534 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.