22442 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.
CWE-79 represents a critical input validation weakness where software fails to properly sanitize user-supplied data before rendering it in web pages. Attackers typically exploit this vulnerability by injecting malicious scripts, often JavaScript, into trusted websites. When other users view the compromised page, the embedded code executes in their browsers, allowing the attacker to steal session cookies, hijack accounts, or redirect victims to phishing sites. This breach of trust undermines user privacy and application integrity. To prevent such attacks, developers must implement robust input validation and output encoding strategies. By strictly filtering incoming data and ensuring that all dynamic content is properly escaped before being processed by the browser, developers can neutralize dangerous inputs and effectively mitigate the risk of cross-site scripting vulnerabilities.
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-54157 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-54778 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-46270 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-55071 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-54852 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-54814 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-54861 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-57881 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58080 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-53854 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-57787 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-53707 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-54853 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-57786 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-44000 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58095 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58092 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58094 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58093 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58091 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58089 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58090 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58088 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-58087 | MedDream PACS Premium 跨站脚本漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-36556 | MedDream PACS Premium 安全漏洞 — MedDream PACS Premium | 6.1 | Medium | 2026-01-20 |
| CVE-2025-15380 | NotificationX <= 3.2.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview' — NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar | 7.2 | High | 2026-01-20 |
| CVE-2026-0608 | Head Meta Data <= 20251118 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta — Head Meta Data | 6.4 | Medium | 2026-01-20 |
| CVE-2026-0690 | FlatPM – Ad Manager, AdSense and Custom Code <= 3.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Post Meta — FlatPM – Ad Manager, AdSense and Custom Code | 6.4 | Medium | 2026-01-20 |
| CVE-2026-1183 | HTML injection in multiple Botble products — TransP | 6.1AI | MediumAI | 2026-01-20 |
| CVE-2025-41025 | Stored Cross-Site Scripting in Poultry Farm Management System — Poultry Farm Management System | 5.4AI | MediumAI | 2026-01-20 |
Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 22442 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.