CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21658 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-11434 | WordPress plugin WP – Bulk SMS – by SMS.to 跨站脚本漏洞 — WP – Bulk SMS – by SMS.to | 6.1 | Medium | 2025-01-07 |
| CVE-2024-12049 | WordPress plugin Woo Ukrposhta 跨站脚本漏洞 — Ukrposhta | 6.1 | Medium | 2025-01-07 |
| CVE-2024-11383 | WordPress plugin CC Canadian Mortgage Calculator 跨站脚本漏洞 — CC Canadian Mortgage Calculator | 6.4 | Medium | 2025-01-07 |
| CVE-2024-11899 | WordPress plugin Slider Pro Lite 跨站脚本漏洞 — Slider Pro Lite | 6.4 | Medium | 2025-01-07 |
| CVE-2024-12098 | WordPress plugin ARS Affiliate Page Plugin 跨站脚本漏洞 — ARS Affiliate Page Plugin | 6.1 | Medium | 2025-01-07 |
| CVE-2024-12592 | WordPress plugin Sellsy 跨站脚本漏洞 — Sellsy | 6.4 | Medium | 2025-01-07 |
| CVE-2024-11777 | WordPress plugin Sell Media 跨站脚本漏洞 — Sell Media | 6.4 | Medium | 2025-01-07 |
| CVE-2024-12528 | WordPress plugin WordPress Survey & Poll 跨站脚本漏洞 — WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress | 6.4 | Medium | 2025-01-07 |
| CVE-2024-11934 | WordPress plugin Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce 跨站脚本漏洞 — Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce | 6.4 | Medium | 2025-01-07 |
| CVE-2024-12590 | WordPress plugin WP Youtube Gallery 跨站脚本漏洞 — WP Youtube Gallery | 6.4 | Medium | 2025-01-07 |
| CVE-2025-21616 | Plane 跨站脚本漏洞 — plane | 5.4 | Medium | 2025-01-06 |
| CVE-2024-31914 | IBM Sterling B2B Integrator 跨站脚本漏洞 — Sterling B2B Integrator Standard Edition | 6.4 | Medium | 2025-01-06 |
| CVE-2024-31913 | IBM Sterling B2B Integrator 跨站脚本漏洞 — Sterling B2B Integrator Standard Edition | 5.5 | Medium | 2025-01-06 |
| CVE-2025-21612 | TabberNeue 跨站脚本漏洞 — mediawiki-extensions-TabberNeue | 8.6 | High | 2025-01-06 |
| CVE-2024-55074 | Grocy 安全漏洞 — Grocy | 8.8 | High | 2025-01-06 |
| CVE-2024-13143 | studentmanager 代码注入漏洞 — studentmanager | 2.4 | Low | 2025-01-05 |
| CVE-2024-13142 | manager-system 代码注入漏洞 — studentmanager | 2.4 | Low | 2025-01-05 |
| CVE-2025-0228 | Code-Projects Local Storage Todo App 代码注入漏洞 — Local Storage Todo App | 2.4 | Low | 2025-01-05 |
| CVE-2024-13141 | LightPicture 代码注入漏洞 — LightPicture | 3.5 | Low | 2025-01-05 |
| CVE-2025-0220 | Trimble SPS851 代码注入漏洞 — SPS851 | 2.4 | Low | 2025-01-05 |
| CVE-2024-13140 | emlog 代码注入漏洞 — Emlog Pro | 3.5 | Low | 2025-01-05 |
| CVE-2024-13137 | Mysiteforme 代码注入漏洞 — mysiteforme | 2.4 | Low | 2025-01-05 |
| CVE-2024-13135 | emlog 代码注入漏洞 — Emlog Pro | 3.5 | Low | 2025-01-05 |
| CVE-2025-0219 | Trimble SPS851 代码注入漏洞 — SPS851 | 2.4 | Low | 2025-01-05 |
| CVE-2024-13132 | emlog 代码注入漏洞 — Emlog Pro | 3.5 | Low | 2025-01-05 |
| CVE-2024-12475 | WordPress plugin WP Multi Store Locator 跨站脚本漏洞 — WP Multistore Locator — WP Store Locator Plugin: Effortless Integration With Snazzy Maps | 6.4 | Medium | 2025-01-04 |
| CVE-2024-12221 | WordPress plugin Turnkey bbPress by WeaverTheme 跨站脚本漏洞 — Turnkey bbPress by WeaverTheme | 6.1 | Medium | 2025-01-04 |
| CVE-2024-11930 | WordPress plugin Taskbuilder 跨站脚本漏洞 — Taskbuilder – Project Management & Task Management Tool With Kanban Board | 6.4 | Medium | 2025-01-04 |
| CVE-2024-11974 | WordPress plugin Media Library Assistant 跨站脚本漏洞 — Media Library Assistant | 6.1 | Medium | 2025-01-04 |
| CVE-2024-12701 | WordPress plugin WP Smart Import 跨站脚本漏洞 — WP Smart Import : Import any XML File to WordPress | 6.1 | Medium | 2025-01-04 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21658 条 CVE 漏洞。