CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21800 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-28142 | Image Access Scan2Net 安全漏洞 — Scan2Net | 5.4 | - | 2024-12-12 |
| CVE-2024-8179 | GitLab 跨站脚本漏洞 — GitLab | 5.4 | Medium | 2024-12-12 |
| CVE-2024-12160 | WordPress plugin Seraphinite Bulk Discounts for WooCommerce 跨站脚本漏洞 — Seraphinite Bulk Discounts for WooCommerce | 6.1 | Medium | 2024-12-12 |
| CVE-2024-11760 | WordPress plugin Currency Converter Widget PRO 跨站脚本漏洞 — Currency Converter Widget ⚡ PRO | 6.4 | Medium | 2024-12-12 |
| CVE-2024-10583 | WordPress plugin Popup Maker 跨站脚本漏洞 — Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | 5.4 | Medium | 2024-12-12 |
| CVE-2024-11727 | WordPress plugin NotificationX 跨站脚本漏洞 — NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar | 4.4 | Medium | 2024-12-12 |
| CVE-2024-10784 | WordPress plugin Unlimited Elements For Elementor (Free Widgets, Addons, Templates) 跨站脚本漏洞 — Unlimited Elements For Elementor | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11766 | WordPress plugin WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more 跨站脚本漏洞 — GS Books Showcase – Display Books in Grid, Slider & More | Library for WordPress | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11052 | WordPress plugin Ninja Forms 跨站脚本漏洞 — Ninja Forms – The Contact Form Builder That Grows With You | 7.2 | High | 2024-12-12 |
| CVE-2024-11871 | WordPress plugin Social Media Shortcodes 跨站脚本漏洞 — Social Media Shortcodes | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11757 | WordPress plugin WP GeoNames 跨站脚本漏洞 — WP GeoNames | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11785 | WordPress plugin Integrate Firebase 跨站脚本漏洞 — Integrate Firebase | 6.4 | Medium | 2024-12-12 |
| CVE-2024-12072 | WordPress plugin Analytics Cat 跨站脚本漏洞 — Analytics Cat – Google Analytics Made Easy | 6.1 | Medium | 2024-12-12 |
| CVE-2024-11765 | WordPress plugin Portfolio 跨站脚本漏洞 — GS Portfolio – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11359 | WordPress plugin Library Bookshelves 跨站脚本漏洞 — Library Bookshelves | 6.1 | Medium | 2024-12-12 |
| CVE-2024-11882 | WordPress plugin FAQ And Answers 跨站脚本漏洞 — Awesome FAQ – Modern Accordion, Tabs,Responsive & Super Fast FAQ Builder. | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11781 | WordPress plugin Smart Agenda 跨站脚本漏洞 — SmartAgenda – Prise de rendez-vous en ligne | 6.4 | Medium | 2024-12-12 |
| CVE-2024-12441 | WordPress plugin BP Email Assign Templates 跨站脚本漏洞 — BP Email Assign Templates | 6.1 | Medium | 2024-12-12 |
| CVE-2024-12156 | WordPress plugin AI Content Writer, RSS Feed to Post, Autoblogging SEO Help 跨站脚本漏洞 — QC SEO Help for llms.txt, AI Analytics, AI Content Writer, Subtitle to Article | 6.1 | Medium | 2024-12-12 |
| CVE-2024-12162 | WordPress plugin Video & Photo Gallery for Ultimate Member 跨站脚本漏洞 — Video & Photo Gallery for Ultimate Member | 6.1 | Medium | 2024-12-12 |
| CVE-2024-11804 | WordPress plugin Planaday API 跨站脚本漏洞 — Planaday API | 6.1 | Medium | 2024-12-12 |
| CVE-2024-11459 | WordPress plugin Country Blocker 跨站脚本漏洞 — Country Blocker | 6.1 | Medium | 2024-12-12 |
| CVE-2024-12463 | WordPress plugin Arena.IM – Live Blogging for real-time events 跨站脚本漏洞 — Arena.IM – Live Blogging for real-time events | 6.4 | Medium | 2024-12-12 |
| CVE-2024-10182 | WordPress plugin Cognito Forms 跨站脚本漏洞 — Cognito Forms | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11384 | WordPress plugin Arena.IM – Live Blogging for real-time events 跨站脚本漏洞 — Arena.IM – Live Blogging for real-time events | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11410 | WordPress plugin YooBar 跨站脚本漏洞 — Yoo Bar – Floating Notification & Promo Bar for Website | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11875 | WordPress plugin Add infos to the events calendar 跨站脚本漏洞 — Add infos to The Events Calendar | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11891 | WordPress plugin Perfect Font Awesome Integration 跨站脚本漏洞 — Perfect Font Awesome Integration | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11750 | WordPress plugin ONLYOFFICE DocSpace 跨站脚本漏洞 — ONLYOFFICE DocSpace | 6.4 | Medium | 2024-12-12 |
| CVE-2024-11723 | WordPress plugin kvCORE IDX 跨站脚本漏洞 — kvCORE IDX | 6.1 | Medium | 2024-12-12 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21800 条 CVE 漏洞。