Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21524

21524 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-24736 Shared Files < 1.6.57 - Admin+ Stored Cross-Site Scripting — Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files 5.4 -2021-10-18
CVE-2021-24734 Compact WP Audio Player < 1.9.7 - Contributor+ Stored Cross-Site Scripting — Compact WP Audio Player 5.4 -2021-10-18
CVE-2021-24732 Dflip Lite < 1.7.10 - Contributor+ Stored Cross-Site Scripting — PDF Flipbook, 3D Flipbook WordPress – DearFlip 5.4 -2021-10-18
CVE-2021-24702 LearnPress < 4.1.3.1 - Multiple Admin+ Stored Cross-Site Scripting — LearnPress – WordPress LMS Plugin 4.8 -2021-10-18
CVE-2021-24672 One User Avatar < 2.3.7 - Contributor+ Stored Cross-Site Scripting — One User Avatar | User Profile Picture 5.4 -2021-10-18
CVE-2021-24622 WP Ticket < 5.10.4 - Admin+ Stored Cross-Site Scripting — Customer Service Software & Support Ticket System 4.8 -2021-10-18
CVE-2021-24617 GamePress <= 1.1.0 - Reflected Cross-Site Scripting — GamePress – The Game Database Plugin 6.1 -2021-10-18
CVE-2021-24612 Sociable <= 4.3.4.1 - Admin+ Stored Cross-Site Scripting — Sociable 4.8 -2021-10-18
CVE-2021-24516 PlanSo Forms <= 2.6.3 - Authenticated Stored Cross-Site Scripting — PlanSo Forms 4.8 -2021-10-18
CVE-2021-24416 StreamCast < 2.1.1 - Contributor+ Stored Cross-Site Scripting — StreamCast – Radio Player for WordPress 5.4 -2021-10-18
CVE-2021-24415 Polo Video Gallery <= 1.2 - Contributor+ Stored Cross-Site Scripting — Polo Video Gallery – Best wordpress video gallery plugin 5.4 -2021-10-18
CVE-2021-24413 Easy Twitter Feed < 1.2 - Contributor+ Stored Cross-Site Scripting — Easy Twitter Feed 5.4 -2021-10-18
CVE-2021-24412 Html5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site Scripting — Html5 Audio Player – Audio Player for WordPress 5.4 -2021-10-18
CVE-2020-8291 Rocket.Chat 跨站脚本漏洞 — Rocket.Chat server 6.1 -2021-10-18
CVE-2021-40721 Adobe Connect Reflected Cross Site Scripting — Connect 6.1 Medium2021-10-15
CVE-2021-39349 Author Bio Box <= 3.3.1 Authenticated Stored Cross-Site Scripting — Author Bio Box 5.5 Medium2021-10-15
CVE-2021-39344 KJM Admin Notices <= 2.0.1 Authenticated Stored Cross-Site Scripting — KJM Admin Notices 5.5 Medium2021-10-15
CVE-2021-39335 WpGenius Job Listing <= 1.0.2 Authenticated Stored Cross-Site Scripting — WpGenius Job Listing 5.5 Medium2021-10-15
CVE-2021-39338 MyBB Cross-Poster <= 1.0 Authenticated Stored Cross-Site Scripting — MyBB Cross-Poster 5.5 Medium2021-10-15
CVE-2021-39345 HAL <= 2.1.1 Authenticated Stored Cross-Site Scripting — HAL 5.5 Medium2021-10-15
CVE-2021-39337 job-portal <= 0.0.1 Authenticated Stored Cross-Site Scripting — job-portal 5.5 Medium2021-10-15
CVE-2021-39336 Job Manager <= 0.7.25 Authenticated Stored Cross-Site Scripting — Job Manager 5.5 Medium2021-10-15
CVE-2021-39334 Job Board Vanila Plugin <= 1.0 Authenticated Stored Cross-Site Scripting — Job Board Vanila Plugin 5.5 Medium2021-10-15
CVE-2021-39332 Business Manager – WordPress ERP, HR, CRM, and Project Management Plugin <= 1.4.5 Authenticated Stored Cross-Site Scripting — Business Manager 5.5 Medium2021-10-15
CVE-2021-42335 Huachu Digital Technology Co.,Ltd. Easytest - Stored XSS — Easytest 5.4 Medium2021-10-15
CVE-2021-42329 ShinHer Information Co., LTD. ShinHer StudyOnline System - Stored XSS — ShinHer StudyOnline System 5.4 Medium2021-10-15
CVE-2021-41142 XSS via the name of a deleted attachment — tuleap 5.4 Medium2021-10-14
CVE-2021-38346 Brizy <= 2.3.11 Authenticated Unrestricted File Upload and Path Traversal — Brizy - Page Builder 8.8 High2021-10-14
CVE-2021-38345 Brizy <= 1.0.125 and 1.0.127 – 2.3.11 Incorrect authorization checks allowing Post modification — Brizy - Page Builder 7.1 High2021-10-14
CVE-2021-38344 Brizy <= 2.3.11 Authenticated Stored Cross-Site Scripting — Brizy - Page Builder 6.4 Medium2021-10-14

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21524 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.