Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21547

21547 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-1529 AM LottiePlayer <= 3.5.3 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Lottie File — AM LottiePlayer 6.4 Medium2025-05-01
CVE-2025-4100 Nautic Pages <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Nautic Pages 6.4 Medium2025-05-01
CVE-2025-4099 List Children <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — List Children 6.4 Medium2025-05-01
CVE-2024-30145 HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability — HCL Domino Leap 6.5 Medium2025-04-30
CVE-2024-30115 HCL Domino Volt and Domino Leap are affected by a cross-site scripting (XSS) vulnerability — HCL Domino Leap 6.3 Medium2025-04-30
CVE-2023-37535 HCL Domino Volt and Domino Leap are affected by a Cross-site scripting (XSS) vulnerability — HCL Domino Leap 7.1 High2025-04-30
CVE-2022-42450 HCL Domino Volt is affected by Cross-site scripting (XSS) — HCL Domino Volt 4.6 Medium2025-04-30
CVE-2025-46558 org.xwiki.contrib.markdown:syntax-markdown-commonmark12 vulnerable to XSS via Markdown content — syntax-markdown 9.1 Critical2025-04-30
CVE-2025-46550 Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting — yeswiki 4.3 Medium2025-04-29
CVE-2025-46549 Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting — yeswiki 4.3 Medium2025-04-29
CVE-2025-4075 VMSMan login.php cross site scripting — VMSMan 4.3 Medium2025-04-29
CVE-2025-46350 Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting — yeswiki 3.5 Low2025-04-29
CVE-2025-46349 YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting — yeswiki 7.6 High2025-04-29
CVE-2025-1551 IBM Operational Decision Manager cross-site scripting — Operational Decision Manager 6.1 Medium2025-04-29
CVE-2025-40616 Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy — Bookgy 6.1AIMediumAI2025-04-29
CVE-2025-40615 Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy — Bookgy 6.1AIMediumAI2025-04-29
CVE-2025-46346 YesWiki Vulnerable to Stored XSS in Comments — yeswiki 5.4AIMediumAI2025-04-29
CVE-2025-3929 Stored XSS vulnerability in MDaemon Email Server — Email Server 6.1AIMediumAI2025-04-29
CVE-2025-2893 Gutenverse <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block — Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem 6.4 Medium2025-04-29
CVE-2025-46343 n8n Vulnerable to Stored XSS through Attachments View Endpoint — n8n 5.0 Medium2025-04-29
CVE-2025-46338 Audiobookshelf Vulnerable to Cross-Site-Scripting Reflected via POST Request in /api/upload — audiobookshelf 5.4AIMediumAI2025-04-29
CVE-2024-11922 Input Validation vulnerability in Web Client emails that do not go through Secure Mail — GoAnywhere MFT 6.3 Medium2025-04-28
CVE-2025-4011 Redmine Custom Query cross site scripting — Redmine 3.5 Low2025-04-28
CVE-2025-4000 Seeyon Zhiyuan OA Web Application System ssoproxy.jsp cross site scripting — Zhiyuan OA Web Application System 3.5 Low2025-04-28
CVE-2025-3999 Seeyon Zhiyuan OA Web Application System URL Parameter date.jsp cross site scripting — Zhiyuan OA Web Application System 3.5 Low2025-04-28
CVE-2025-3706 104 Corporation eHRMS - Reflected Cross-Site Scripting — eHRMS 6.1 Medium2025-04-28
CVE-2025-3996 TOTOLINK N150RT MAC Filtering Page home.htm cross site scripting — N150RT 2.4 Low2025-04-28
CVE-2025-3995 TOTOLINK N150RT LAN Settings Page fromStaticDHCP cross site scripting — N150RT 2.4 Low2025-04-28
CVE-2025-3994 TOTOLINK N150RT IP Port Filtering home.htm cross site scripting — N150RT 2.4 Low2025-04-28
CVE-2015-4582 WordPress plugin TheCartPress boot-store 安全漏洞 — boot-store 7.2 High2025-04-28

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21547 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.