Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) — Vulnerability Class 21524

21524 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-8589 Reflected XSS in AKCE Software's SKSPro — SKSPro 7.6 High2026-02-03
CVE-2026-1058 Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder 7.1 High2026-02-03
CVE-2026-1210 Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field — Happy Addons for Elementor 6.4 Medium2026-02-03
CVE-2026-0617 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting — LatePoint – Calendar Booking Plugin for Appointments and Events 7.2 High2026-02-03
CVE-2025-14274 Unlimited Elements for Elementor <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget — Unlimited Elements For Elementor 5.4 Medium2026-02-03
CVE-2025-67481 mw.message(…).parse() doesn't output safe HTML, but it's being used as if it does — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-67483 Theoretical i18n XSS in mediawiki.page.preview.js when a page has multiple protection levels — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-67475 Stored XSS through edit summaries in MW Core — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-67477 Stored XSS through a system message in Special:ApiSandbox — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-61655 Stored XSS through system messages in VisualEditor — VisualEditor 6.1AIMediumAI2026-02-03
CVE-2025-61656 XSS when pasting into VE — VisualEditor 6.1AIMediumAI2026-02-03
CVE-2025-61657 Wikimedia Vector 安全漏洞 — Vector 6.1AIMediumAI2026-02-03
CVE-2025-61651 i18n XSS through Special:CheckUser CheckUser helper — CheckUser 6.1AIMediumAI2026-02-03
CVE-2025-11261 Stored i18n XSS exposed by security patch for T402077 — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-61648 Stored XSS through system messages in CheckUser — CheckUser 6.1AIMediumAI2026-02-03
CVE-2025-61650 UserInfoCard is vulnerable to message key stored XSS — CheckUser 6.1AIMediumAI2026-02-03
CVE-2025-61645 CodexTablePager has i18n XSS — MediaWiki 6.1AIMediumAI2026-02-03
CVE-2025-61644 i18n XSS through Special:Watchlist — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61637 Stored XSS through system messages in MW Core — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61638 Sanitizer::validateAttributes data-XSS — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61640 Stored XSS through system messages in Special:RecentChangesLinked (MW Core) — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61642 Stored XSS through system messages provided to CodexHtmlForms — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-61636 Codex Special:Block vulnerable to message key XSS — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-6594 XSS in Special:ApiSandbox — MediaWiki 6.1AIMediumAI2026-02-02
CVE-2025-6595 MediaWiki 安全漏洞 — MultimediaViewer 6.1AIMediumAI2026-02-02
CVE-2025-6596 Vector inserts portlet labels as HTML, allowing for stored XSS through system messages — Vector 6.1AIMediumAI2026-02-02
CVE-2026-25144 Talishar has a Stored XSS which can lead to data exfiltration & user impersonation — Talishar 5.3 Medium2026-02-02
CVE-2025-36436 Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for January 2026. — Cloud Pak for Business Automation 6.4 Medium2026-02-02
CVE-2026-23476 FacturaScripts Affected by Reflected XSS — facturascripts 5.4 Medium2026-02-02
CVE-2026-23997 FacturaScripts has a Stored Cross-Site Scripting (XSS) in "Observations" field via History View — facturascripts 8.0 High2026-02-02

Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21524 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.