Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21527

21527 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-36919 WordPress Awesome Support plugin <= 6.0.6 - Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities — Awesome Support (WordPress plugin) 6.1 Medium2021-11-26
CVE-2021-36843 WordPress Floating Social Media Icon plugin <= 4.3.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability — Floating Social Media Icon (WordPress plugin) 4.8 Medium2021-11-26
CVE-2021-25986 Django-wiki - Stored Cross-Site Scripting (XSS) in Notifications Section — Django-wiki 5.4 Medium2021-11-23
CVE-2021-31851 Cross-Site Scripting vulnerability in Policy Auditor — McAfee Policy Auditor 6.1 Medium2021-11-23
CVE-2021-31852 Cross-Site Scripting vulnerability in Policy Auditor — McAfee Policy Auditor 6.1 Medium2021-11-23
CVE-2021-24891 Elementor < 3.4.8 - DOM Cross-Site-Scripting — Elementor Website Builder 6.1 -2021-11-23
CVE-2021-24888 ImageBoss < 3.0.6 - Admin+ Stored Cross-Site Scripting — ImageBoss – Images Up To 60% Smaller & CDN 4.8 -2021-11-23
CVE-2021-24882 Slideshow Gallery < 1.7.4 - Admin+ Stored Cross-Site Scripting — Slideshow Gallery 4.8 -2021-11-23
CVE-2021-24875 eCommerce Product Catalog for WordPress < 3.0.39 - Reflected Cross-Site Scripting — eCommerce Product Catalog Plugin for WordPress 6.1 -2021-11-23
CVE-2021-24873 Tutor LMS < 1.9.11 - Reflected Cross-Site Scripting — Tutor LMS – eLearning and online course solution 6.1 -2021-11-23
CVE-2021-24830 Advanced Access Manager < 6.8.0 - Admin+ Stored Cross-Site Scripting — Advanced Access Manager 4.8 -2021-11-23
CVE-2021-24812 BetterLinks < 1.2.6 - Admin+ Stored Cross-Site Scripting — BetterLinks – Shorten, Track and Manage any URL 5.4 -2021-11-23
CVE-2021-24729 Logo Showcase with Slick Slider < 1.2.4 - Author+ Stored Cross Site Scripting — Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid 5.4 -2021-11-23
CVE-2021-24713 Video Lessons Manager - Admin+ Stored Cross-Site Scripting — Video Lessons Manager – Best Video Course LMS 4.8 -2021-11-23
CVE-2021-24700 Forminator < 1.15.4 - Admin+ Stored Cross-Site Scripting — Forminator – Contact Form, Payment Form & Custom Form Builder 4.8 -2021-11-23
CVE-2021-3672 libcares2 跨站脚本漏洞 — c-ares 5.6 -2021-11-23
CVE-2021-43558 Moodle 跨站脚本漏洞 — moodle 6.1 -2021-11-22
CVE-2021-38681 Reflected XSS Vulnerability in Ragic Cloud DB — Ragic Cloud DB 5.3 Medium2021-11-20
CVE-2021-36884 WordPress Backup Migration plugin <= 1.1.5 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability — Backup Migration (WordPress plugin) 4.8 Medium2021-11-19
CVE-2021-43409 WPO365 | LOGIN - Wordpress Plugin Persistent Cross-Site Scripting — WordPress + Microsoft Office 365 / Azure AD | LOGIN 9.3 Critical2021-11-19
CVE-2021-42363 Preview E-Mails for WooCommerce <= 1.6.8 Reflected Cross-Site Scripting — Preview E-Mails for WooCommerce 6.1 Medium2021-11-19
CVE-2021-3920 Cross-site Scripting (XSS) - Stored in getgrav/grav-plugin-admin — getgrav/grav-plugin-admin 5.4 -2021-11-19
CVE-2021-3950 Cross-site Scripting (XSS) - Stored in django-helpdesk/django-helpdesk — django-helpdesk/django-helpdesk 6.1 -2021-11-19
CVE-2021-3961 Cross-site Scripting (XSS) - Stored in snipe/snipe-it — snipe/snipe-it 5.4 -2021-11-19
CVE-2021-43549 OSIsoft PI Web API — PI Web API 6.9 Medium2021-11-18
CVE-2021-41165 HTML comments vulnerability allowing to execute JavaScript code — ckeditor4 8.2 High2021-11-17
CVE-2021-42361 Contact Form Email <= 1.3.24 Authenticated Stored Cross-Site Scripting — Contact Form Email 4.8 Medium2021-11-17
CVE-2021-43551 OSIsoft PI Vision — PI Vision 6.5 Medium2021-11-17
CVE-2021-24856 Shared Files < 1.6.61 - Admin+ Stored Cross-Site Scripting — Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload 4.8 -2021-11-17
CVE-2021-24854 QR Redirector < 1.6.1 - Contributor+ Stored Cross-Site Scripting — QR Redirector 5.4 -2021-11-17

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21527 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.