CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21788 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-11192 | WordPress plugin Spotify Play Button 跨站脚本漏洞 — Sp*tify Play Button for WordPress | 6.4 | Medium | 2024-11-26 |
| CVE-2024-9170 | WordPress plugin WordPress Booster for WooCommerce 跨站脚本漏洞 — Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools | 5.5 | Medium | 2024-11-26 |
| CVE-2024-36249 | Sharp MFP和Toshiba MFP 跨站脚本漏洞 — Multiple MFPs (multifunction printers) | 7.4 | High | 2024-11-26 |
| CVE-2024-11202 | WordPress plugin多款产品 跨站脚本漏洞 — CM Header and Footer – Add custom scripts and styles to your header and footer with ease | 6.1 | Medium | 2024-11-26 |
| CVE-2024-53278 | WordPress plugin WP Admin UI Customize 跨站脚本漏洞 — WP Admin UI Customize | 4.8AI | MediumAI | 2024-11-26 |
| CVE-2024-11418 | WordPress plugin Additional Order Filters for WooCommerce 跨站脚本漏洞 — Additional Order Filters for WooCommerce | 6.1 | Medium | 2024-11-26 |
| CVE-2024-11678 | CodeAstro Hospital Management System 安全漏洞 — Hospital Management System | 3.5 | Low | 2024-11-26 |
| CVE-2024-11677 | CodeAstro Hospital Management System 安全漏洞 — Hospital Management System | 3.5 | Low | 2024-11-26 |
| CVE-2024-11676 | CodeAstro Hospital Management System 安全漏洞 — Hospital Management System | 3.5 | Low | 2024-11-26 |
| CVE-2024-11675 | CodeAstro Hospital Management System 安全漏洞 — Hospital Management System | 3.5 | Low | 2024-11-26 |
| CVE-2024-53843 | keycloak-connector 跨站脚本漏洞 — keycloak-connector | 8.1 | High | 2024-11-25 |
| CVE-2024-53261 | SvelteKit 跨站脚本漏洞 — kit | 6.1AI | MediumAI | 2024-11-25 |
| CVE-2024-53262 | SvelteKit 跨站脚本漏洞 — kit | 7.1AI | HighAI | 2024-11-25 |
| CVE-2024-53255 | BoidCMS 安全漏洞 — BoidCMS | 6.1AI | MediumAI | 2024-11-25 |
| CVE-2024-32468 | Deno 跨站脚本漏洞 — deno | 5.4 | Medium | 2024-11-25 |
| CVE-2024-51723 | BlackBerry AtHoc 安全漏洞 — AtHoc | 4.6 | Medium | 2024-11-25 |
| CVE-2023-45181 | IBM Jazz Foundation 跨站脚本漏洞 — Jazz Foundation | 6.1 | Medium | 2024-11-25 |
| CVE-2021-23282 | Eaton Intelligent Power Manager 跨站脚本漏洞 — Intelligent Power Manager (IPM) | 5.2 | Medium | 2024-11-25 |
| CVE-2024-11660 | Farmacia 安全漏洞 — Farmacia | 3.5 | Low | 2024-11-25 |
| CVE-2024-11228 | WordPress plugin 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 跨站脚本漏洞 — 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 | 6.4 | Medium | 2024-11-23 |
| CVE-2024-11229 | WordPress plugin 코드엠샵 소셜톡 跨站脚本漏洞 — 코드엠샵 소셜톡 | 6.4 | Medium | 2024-11-23 |
| CVE-2024-11231 | WordPress plugin 우커머스 네이버페이 跨站脚本漏洞 — 우커머스 네이버페이 | 6.4 | Medium | 2024-11-23 |
| CVE-2024-10519 | WordPress plugin Wishlist for WooCommerce 跨站脚本漏洞 — Wishlist for WooCommerce: Multi Wishlists Per Customer PRO | 6.1 | Medium | 2024-11-23 |
| CVE-2024-11199 | WordPress plugin Rescue Shortcodes 跨站脚本漏洞 — Rescue Shortcodes | 6.4 | Medium | 2024-11-23 |
| CVE-2024-11227 | WordPress plugin Memberlite Shortcodes 跨站脚本漏洞 — Memberlite Shortcodes | 6.4 | Medium | 2024-11-23 |
| CVE-2024-9635 | WordPress plugin Checkout with Cash App on WooCommerce 跨站脚本漏洞 — Checkout with Cash App on WooCommerce | 6.1 | Medium | 2024-11-23 |
| CVE-2024-11446 | WordPress plugin Chessgame Shizzle 跨站脚本漏洞 — Chessgame Shizzle | 6.1 | Medium | 2024-11-23 |
| CVE-2024-11330 | WordPress plugin Custom CSS, JS & PHP 跨站脚本漏洞 — Custom CSS, JS & PHP | 6.1 | Medium | 2024-11-23 |
| CVE-2024-11188 | WordPress plugin Formidable Forms 跨站脚本漏洞 — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder | 6.1 | Medium | 2024-11-23 |
| CVE-2024-11361 | WordPress plugin PDF Invoices & Packing Slips Generator for WooCommerce 跨站脚本漏洞 — PDF Invoices & Packing Slips Generator for WooCommerce | 6.1 | Medium | 2024-11-23 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21788 条 CVE 漏洞。