Bundled Themes: Consistently escape get_search_query() in search.php templates.

Props sabernhardt, himshekhar07, petitphp, karmatosed, SergeyBiryukov.
Fixes #58127.
Built from https://develop.svn.wordpress.org/trunk@61427


git-svn-id: http://core.svn.wordpress.org/trunk@60739 1a063a9b-81f0-0310-95a4-ce76da25c4cd
This commit is contained in:
Sergey Biryukov
2026-01-03 22:26:34 +00:00
parent ca8b023f84
commit 44deb16935
13 changed files with 14 additions and 14 deletions

View File

@@ -18,7 +18,7 @@ get_header(); ?>
<h1 class="page-title">
<?php
/* translators: %s: Search query. */
printf( __( 'Search Results for: %s', 'twentyeleven' ), '<span>' . get_search_query() . '</span>' );
printf( __( 'Search Results for: %s', 'twentyeleven' ), '<span>' . esc_html( get_search_query( false ) ) . '</span>' );
?>
</h1>
</header>

View File

@@ -18,7 +18,7 @@ get_header(); ?>
<h1 class="page-title">
<?php
/* translators: %s: Search query. */
printf( __( 'Search Results for: %s', 'twentyfifteen' ), get_search_query() );
printf( __( 'Search Results for: %s', 'twentyfifteen' ), esc_html( get_search_query( false ) ) );
?>
</h1>
</header><!-- .page-header -->

View File

@@ -18,7 +18,7 @@ get_header(); ?>
<h1 class="page-title">
<?php
/* translators: %s: Search query. */
printf( __( 'Search Results for: %s', 'twentyfourteen' ), get_search_query() );
printf( __( 'Search Results for: %s', 'twentyfourteen' ), esc_html( get_search_query( false ) ) );
?>
</h1>
</header><!-- .page-header -->

View File

@@ -20,7 +20,7 @@ get_header();
<header class="page-header">
<h1 class="page-title">
<?php _e( 'Search results for: ', 'twentynineteen' ); ?>
<span class="page-description"><?php echo get_search_query(); ?></span>
<span class="page-description"><?php echo esc_html( get_search_query( false ) ); ?></span>
</h1>
</header><!-- .page-header -->

View File

@@ -19,7 +19,7 @@ get_header(); ?>
<h1 class="page-title">
<?php
/* translators: Search query. */
printf( __( 'Search Results for: %s', 'twentyseventeen' ), '<span>' . get_search_query() . '</span>' );
printf( __( 'Search Results for: %s', 'twentyseventeen' ), '<span>' . esc_html( get_search_query( false ) ) . '</span>' );
?>
</h1>
<?php else : ?>

View File

@@ -18,7 +18,7 @@ get_header(); ?>
<h1 class="page-title">
<?php
/* translators: %s: The search query. */
printf( __( 'Search Results for: %s', 'twentysixteen' ), '<span>' . esc_html( get_search_query() ) . '</span>' );
printf( __( 'Search Results for: %s', 'twentysixteen' ), '<span>' . esc_html( get_search_query( false ) ) . '</span>' );
?>
</h1>
</header><!-- .page-header -->

View File

@@ -16,7 +16,7 @@ get_header(); ?>
<h1 class="page-title">
<?php
/* translators: %s: Search query. */
printf( __( 'Search Results for: %s', 'twentyten' ), '<span>' . get_search_query() . '</span>' );
printf( __( 'Search Results for: %s', 'twentyten' ), '<span>' . esc_html( get_search_query( false ) ) . '</span>' );
?>
</h1>
<?php

View File

@@ -18,7 +18,7 @@ get_header(); ?>
<h1 class="page-title">
<?php
/* translators: %s: Search query. */
printf( __( 'Search Results for: %s', 'twentythirteen' ), get_search_query() );
printf( __( 'Search Results for: %s', 'twentythirteen' ), esc_html( get_search_query( false ) ) );
?>
</h1>
</header>

View File

@@ -18,7 +18,7 @@ get_header(); ?>
<h1 class="page-title">
<?php
/* translators: %s: Search query. */
printf( __( 'Search Results for: %s', 'twentytwelve' ), '<span>' . get_search_query() . '</span>' );
printf( __( 'Search Results for: %s', 'twentytwelve' ), '<span>' . esc_html( get_search_query( false ) ) . '</span>' );
?>
</h1>
</header>

View File

@@ -31,9 +31,9 @@ get_header();
global $wp_query;
$archive_title = sprintf(
'%1$s %2$s',
'%1$s &ldquo;%2$s&rdquo;',
'<span class="color-accent">' . __( 'Search:', 'twentytwenty' ) . '</span>',
'&ldquo;' . get_search_query() . '&rdquo;'
esc_html( get_search_query( false ) )
);
if ( $wp_query->found_posts ) {

View File

@@ -19,7 +19,7 @@ if ( have_posts() ) {
printf(
/* translators: %s: Search term. */
esc_html__( 'Results for "%s"', 'twentytwentyone' ),
'<span class="page-description search-term">' . esc_html( get_search_query() ) . '</span>'
'<span class="page-description search-term">' . esc_html( get_search_query( false ) ) . '</span>'
);
?>
</h1>

View File

@@ -20,7 +20,7 @@
printf(
/* translators: %s: Search term. */
esc_html__( 'Results for "%s"', 'twentytwentyone' ),
'<span class="page-description search-term">' . esc_html( get_search_query() ) . '</span>'
'<span class="page-description search-term">' . esc_html( get_search_query( false ) ) . '</span>'
);
?>
</h1>

View File

@@ -16,7 +16,7 @@
*
* @global string $wp_version
*/
$wp_version = '7.0-alpha-61426';
$wp_version = '7.0-alpha-61427';
/**
* Holds the WordPress DB revision, increments when changes are made to the WordPress DB schema.