CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21787 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-11420 | WordPress plugin Blocksy 跨站脚本漏洞 — Blocksy | 6.4 | Medium | 2024-12-05 |
| CVE-2024-10178 | WordPress plugin Gutentor 跨站脚本漏洞 — Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor | 6.4 | Medium | 2024-12-05 |
| CVE-2024-10881 | WordPress plugin LUNA RADIO PLAYER 跨站脚本漏洞 — LUNA RADIO PLAYER | 6.4 | Medium | 2024-12-05 |
| CVE-2024-12183 | DesDev DedeCMS 代码注入漏洞 — DedeCMS | 3.5 | Low | 2024-12-04 |
| CVE-2024-12182 | DesDev DedeCMS 代码注入漏洞 — DedeCMS | 3.5 | Low | 2024-12-04 |
| CVE-2024-12181 | DesDev DedeCMS 代码注入漏洞 — DedeCMS | 3.5 | Low | 2024-12-04 |
| CVE-2024-12180 | DesDev DedeCMS 代码注入漏洞 — DedeCMS | 3.5 | Low | 2024-12-04 |
| CVE-2024-40745 | Joomla! 安全漏洞 — Convert Forms component for Joomla | 6.1 | - | 2024-12-04 |
| CVE-2024-11935 | WordPress plugin Email Address Obfuscation 跨站脚本漏洞 — Email Address Obfuscation | 6.4 | Medium | 2024-12-04 |
| CVE-2024-8962 | WordPress plugin WPBITS Addons For Elementor Page Builder 跨站脚本漏洞 — WPBITS Addons For Elementor Page Builder | 6.4 | Medium | 2024-12-04 |
| CVE-2024-11854 | WordPress plugin Listdom 跨站脚本漏洞 — Listdom: AI-powered Business Directory with Classifieds Ads Listings | 6.4 | Medium | 2024-12-04 |
| CVE-2024-11814 | WordPress plugin Additional Custom Order Status for WooCommerce 跨站脚本漏洞 — Additional Custom Order Status for WooCommerce | 6.1 | Medium | 2024-12-04 |
| CVE-2024-5020 | WordPress plugin多款产品 跨站脚本漏洞 — Colibri Page Builder | 6.4 | Medium | 2024-12-04 |
| CVE-2024-11880 | WordPress plugin B Testimonial 跨站脚本漏洞 — B Testimonial – Customer Testimonials in Custom Layouts | 6.4 | Medium | 2024-12-04 |
| CVE-2024-11903 | WordPress plugin WP eCards 跨站脚本漏洞 — WP eCards – Branded Digital Greeting Cards | 6.4 | Medium | 2024-12-04 |
| CVE-2023-6978 | WordPress plugin WP Job Manager – Company Profiles 跨站脚本漏洞 — WP Job Manager – Company Profiles | 6.1 | Medium | 2024-12-04 |
| CVE-2024-11769 | WordPress plugin Flower Delivery by Florist One 跨站脚本漏洞 — Flower Delivery by Florist One | 6.4 | Medium | 2024-12-04 |
| CVE-2024-11466 | WordPress plugin Intro Tour Tutorial DeepPresentation 跨站脚本漏洞 — Intro Tour Tutorial DeepPresentation | 6.1 | Medium | 2024-12-04 |
| CVE-2024-45717 | SolarWinds Platform 跨站脚本漏洞 — SolarWinds Platform | 7.0 | High | 2024-12-04 |
| CVE-2024-10885 | WordPress plugin SearchIQ 跨站脚本漏洞 — SearchIQ – The Search Solution | 6.4 | Medium | 2024-12-04 |
| CVE-2024-11807 | WordPress plugin NPS computy 跨站脚本漏洞 — NPS computy | 6.1 | Medium | 2024-12-04 |
| CVE-2024-11747 | WordPress plugin Responsive Videos 跨站脚本漏洞 — Responsive Videos | 6.4 | Medium | 2024-12-04 |
| CVE-2024-11897 | WordPress plugin MightyForms 跨站脚本漏洞 — Contact Form, Survey & Form Builder – MightyForms | 6.4 | Medium | 2024-12-04 |
| CVE-2024-11093 | WordPress plugin SG Helper 跨站脚本漏洞 — SG Helper | 5.5 | Medium | 2024-12-04 |
| CVE-2024-10832 | WordPress plugin Posti Shipping 跨站请求伪造漏洞 — Posti Shipping | 6.1 | Medium | 2024-12-04 |
| CVE-2024-11479 | Issuetrak 安全漏洞 — Issuetrak | 4.6 | - | 2024-12-04 |
| CVE-2024-53257 | Vitess 安全漏洞 — vitess | 4.9 | Medium | 2024-12-03 |
| CVE-2024-53999 | Mobile Security Framework 安全漏洞 — Mobile-Security-Framework-MobSF | 8.1 | High | 2024-12-03 |
| CVE-2024-11200 | WordPress plugin Goodlayers Core 跨站脚本漏洞 — Goodlayers Core | 6.1 | Medium | 2024-12-03 |
| CVE-2024-11326 | WordPress plugin Campaign Monitor Forms by Optin Cat 跨站脚本漏洞 — Campaign Monitor Forms by Optin Cat | 6.1 | Medium | 2024-12-03 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21787 条 CVE 漏洞。