Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21517

21517 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-25355 WordPress Sanzo theme < 2.4.3 - Cross Site Scripting (XSS) vulnerability — Sanzo 6.5 Medium2026-03-25
CVE-2026-25353 WordPress Nooni theme < 1.5.1 - Reflected Cross Site Scripting (XSS) vulnerability — Nooni 7.1 High2026-03-25
CVE-2026-25351 WordPress MyMedi theme < 1.7.7 - Reflected Cross Site Scripting (XSS) vulnerability — MyMedi 7.1 High2026-03-25
CVE-2026-25350 WordPress Miti theme < 1.5.3 - Reflected Cross Site Scripting (XSS) vulnerability — Miti 7.1 High2026-03-25
CVE-2026-25346 WordPress FAQ Builder AYS plugin <= 1.8.2 - Cross Site Scripting (XSS) vulnerability — FAQ Builder AYS 6.1 -2026-03-25
CVE-2026-25347 WordPress WP REST Cache plugin <= 2026.1.0 - Cross Site Scripting (XSS) vulnerability — WP REST Cache 7.1 High2026-03-25
CVE-2026-25349 WordPress Loobek theme < 1.5.2 - Reflected Cross Site Scripting (XSS) vulnerability — Loobek 7.1 High2026-03-25
CVE-2026-25342 WordPress Boutique theme < 2.4.6 - Reflected Cross Site Scripting (XSS) vulnerability — Boutique 7.1 High2026-03-25
CVE-2026-25341 WordPress RSFirewall! plugin <= 1.1.45 - Cross Site Scripting (XSS) vulnerability — RSFirewall! 7.1 High2026-03-25
CVE-2026-25304 WordPress Jaroti theme < 1.4.8 - Reflected Cross Site Scripting (XSS) vulnerability — Jaroti 7.1 High2026-03-25
CVE-2026-25033 WordPress Motta Addons plugin < 1.6.1 - Reflected Cross Site Scripting (XSS) vulnerability — Motta Addons 7.1 High2026-03-25
CVE-2026-25306 WordPress XStore Core plugin <= 5.6.4 - Reflected Cross Site Scripting (XSS) vulnerability — XStore Core 7.1 High2026-03-25
CVE-2026-25025 WordPress VikRestaurants plugin <= 1.5.2 - Reflected Cross Site Scripting (XSS) vulnerability — VikRestaurants 7.1 High2026-03-25
CVE-2026-25018 WordPress NaturaLife Extensions plugin <= 2.1 - Reflected Cross Site Scripting (XSS) vulnerability — NaturaLife Extensions 7.1 High2026-03-25
CVE-2026-25013 WordPress Phox Hosting plugin <= 2.0.8 - Reflected Cross Site Scripting (XSS) vulnerability — Phox Hosting 7.1 High2026-03-25
CVE-2026-24983 WordPress UpSolution Core plugin <= 8.41 - Reflected Cross Site Scripting (XSS) vulnerability — UpSolution Core 7.1 High2026-03-25
CVE-2026-24980 WordPress Visionary Core plugin <= 1.4.9 - Reflected Cross Site Scripting (XSS) vulnerability — Visionary Core 7.1 High2026-03-25
CVE-2026-24975 WordPress Organici Library plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerability — Organici Library 7.1 High2026-03-25
CVE-2026-24979 WordPress Jobica Core plugin <= 1.4.1 - Reflected Cross Site Scripting (XSS) vulnerability — Jobica Core 7.1 High2026-03-25
CVE-2026-24973 WordPress CitiLights theme <= 3.7.1 - Reflected Cross Site Scripting (XSS) vulnerability — CitiLights 7.1 High2026-03-25
CVE-2026-24391 WordPress Car Dealer theme <= 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability — Car Dealer 7.1 High2026-03-25
CVE-2026-24370 WordPress The Grid plugin < 2.8.0 - Cross Site Scripting (XSS) vulnerability — The Grid 6.5 Medium2026-03-25
CVE-2026-23979 WordPress Gyan Elements plugin <= 2.2.1 - Reflected Cross Site Scripting (XSS) vulnerability — Gyan Elements 7.1 High2026-03-25
CVE-2026-23807 WordPress WP Telegram Widget and Join Link plugin <= 2.2.13 - Reflected Cross Site Scripting (XSS) vulnerability — WP Telegram Widget and Join Link 7.1 High2026-03-25
CVE-2026-23973 WordPress Golo theme < 1.7.5 - Reflected Cross Site Scripting (XSS) vulnerability — Golo 7.1 High2026-03-25
CVE-2026-22524 WordPress Legacy Admin plugin <= 9.5 - Reflected Cross Site Scripting (XSS) vulnerability — Legacy Admin 7.1 High2026-03-25
CVE-2026-22523 WordPress Ultra WordPress Admin plugin <= 11.7 - Reflected Cross Site Scripting (XSS) vulnerability — Ultra WordPress Admin 7.1 High2026-03-25
CVE-2026-22520 WordPress Handmade Framework plugin <= 3.9 - Reflected Cross Site Scripting (XSS) vulnerability — Handmade Framework 7.1 High2026-03-25
CVE-2026-22491 WordPress My auctions allegro plugin <= 3.6.35 - Cross Site Scripting (XSS) vulnerability — My auctions allegro 7.1 High2026-03-25
CVE-2025-69096 WordPress Zorka theme <= 1.5.7 - Reflected Cross Site Scripting (XSS) vulnerability — Zorka 7.1 High2026-03-25

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21517 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.