Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21529

21529 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-24895 Cybersoldier < 1.7.0 - Admin+ Stored Cross-Site Scripting — Cybersoldier 4.8 -2022-03-14
CVE-2022-0946 Stored XSS viva cshtm file upload in star7th/showdoc — star7th/showdoc 5.4 -2022-03-14
CVE-2022-0941 Stored XSS due to Unrestricted File Upload in star7th/showdoc — star7th/showdoc 5.4 -2022-03-14
CVE-2022-0940 Stored XSS due to Unrestricted File Upload in star7th/showdoc — star7th/showdoc 5.4 -2022-03-14
CVE-2022-0938 Stored XSS via file upload in star7th/showdoc — star7th/showdoc 5.4 -2022-03-14
CVE-2022-0341 Cross-site Scripting (XSS) - Stored in vanessa219/vditor — vanessa219/vditor 5.4 -2022-03-14
CVE-2022-0937 Stored xss in showdoc through file upload in star7th/showdoc — star7th/showdoc 5.4 -2022-03-14
CVE-2022-24384 Reflective XSS on SmarterTrack v100.0.8019.14010 — SmarterTrack 8.8 High2022-03-14
CVE-2022-24386 Stored XSS in SmarterTrack v100.0.8019.14010 — SmarterTrack 8.8 High2022-03-14
CVE-2022-0929 XSS on dynamic_text module in microweber/microweber — microweber/microweber 6.1 -2022-03-12
CVE-2022-0926 File upload filter bypass leading to stored XSS in microweber/microweber — microweber/microweber 4.8 -2022-03-12
CVE-2022-0880 Cross-site Scripting (XSS) - Stored in star7th/showdoc — star7th/showdoc 5.4 -2022-03-12
CVE-2022-25601 WordPress Contact Form X plugin <= 2.4 - Reflected Cross-Site Scripting (XSS) vulnerability — Contact Form X (WordPress plugin) 4.7 Medium2022-03-11
CVE-2021-27416 Cross-site scripting in Hitachi ABB Power Grids Ellipse EAM — Ellipse Enterprise Asset Management (EAM) 5.5 Medium2022-03-11
CVE-2021-32009 Missing XSS guards on firmware page — GateManager 5.0 Medium2022-03-11
CVE-2022-0928 Cross-site Scripting (XSS) - Stored in microweber/microweber — microweber/microweber 4.8 -2022-03-11
CVE-2022-0822 Cross-site Scripting (XSS) - Reflected in orchardcms/orchardcore — orchardcms/orchardcore 6.1 -2022-03-11
CVE-2021-32478 Moodle 输入验证错误漏洞 — moodle 6.1 -2022-03-11
CVE-2022-0820 Cross-site Scripting (XSS) - Stored in orchardcms/orchardcore — orchardcms/orchardcore 5.4 -2022-03-10
CVE-2022-0906 Unrestricted file upload leads to stored XSS in microweber/microweber — microweber/microweber 4.8 -2022-03-10
CVE-2022-24746 HTML injection possibility in voucher code form — platform 6.1 Medium2022-03-09
CVE-2022-22511 WAGO PLCs WBM vulnerable to reflected XSS — Compact Controller CC100 (751-9301) 5.4 Medium2022-03-09
CVE-2022-24919 Reflected XSS in graph configuration window of Zabbix Frontend — Frontend 3.7 Low2022-03-09
CVE-2022-24918 Reflected XSS in item configuration window of Zabbix Frontend — Frontend 3.7 Low2022-03-09
CVE-2022-24917 Reflected XSS in service configuration window of Zabbix Frontend — Frontend 3.7 Low2022-03-09
CVE-2022-24349 Reflected XSS in action configuration window of Zabbix Frontend — Frontend 4.6 Medium2022-03-09
CVE-2021-33852 WordPress Plugin Post-Duplicator Plugin 跨站脚本漏洞 — WordPress Post Duplicator Plugin 5.4 -2022-03-09
CVE-2021-33851 WordPress Plugin 跨站脚本漏洞 — WordPress Customize Login Image Plugin 5.4 -2022-03-09
CVE-2022-24397 SAP Enterprise Portal 跨站脚本漏洞 — SAP NetWeaver Enterprise Portal 6.1 -2022-03-09
CVE-2022-24432 ICSA-22-062-01 IPCOMM ipDIO — IPCOMM ipDIO 5.5 Medium2022-03-09

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21529 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.