CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21801 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-10419 | Code-Projects Blood Bank Management System 跨站脚本漏洞 — Blood Bank Management System | 3.5 | Low | 2024-10-27 |
| CVE-2024-10414 | PHPGurukul Vehicle Record System 跨站脚本漏洞 — Vehicle Record System | 2.4 | Low | 2024-10-27 |
| CVE-2024-10412 | Guns-Medical 跨站脚本漏洞 — Guns-Medical | 3.5 | Low | 2024-10-27 |
| CVE-2024-10117 | WordPress plugin WP Crowdfunding 跨站脚本漏洞 — WP Crowdfunding | 6.4 | Medium | 2024-10-26 |
| CVE-2024-9116 | WordPress plugin Monkee-Boy Essentials 安全漏洞 — Monkee-Boy Essentials | 6.4 | Medium | 2024-10-26 |
| CVE-2024-9642 | WordPress plugin Editor Custom Color Palette 跨站脚本漏洞 — Editor Custom Color Palette | 6.4 | Medium | 2024-10-26 |
| CVE-2024-9967 | WordPress plugin WP show more 跨站脚本漏洞 — WP show more | 6.4 | Medium | 2024-10-26 |
| CVE-2024-9853 | WordPress plugin ID-SK Toolkit 跨站脚本漏洞 — ID-SK Toolkit | 6.4 | Medium | 2024-10-26 |
| CVE-2024-9456 | WordPress plugin WP Awesome Login 跨站脚本漏洞 — WP Awesome Login | 6.4 | Medium | 2024-10-26 |
| CVE-2024-8870 | WordPress plugin Forms for Mailchimp by Optin Cat 跨站脚本漏洞 — Forms for Mailchimp by Optin Cat – Grow Your MailChimp List | 6.1 | Medium | 2024-10-26 |
| CVE-2024-9613 | WordPress plugin FormFacade 跨站脚本漏洞 — FormFacade – Embed Google Forms in your website | 6.1 | Medium | 2024-10-26 |
| CVE-2024-9454 | WordPress plugin PriPre 跨站脚本漏洞 — PriPre | 6.4 | Medium | 2024-10-26 |
| CVE-2024-10091 | WordPress plugin ElementsKit Elementor addons 跨站脚本漏洞 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor | 6.4 | Medium | 2024-10-26 |
| CVE-2024-9462 | WordPress plugin Poll Maker 跨站脚本漏洞 — Poll Maker – Versus Polls, Anonymous Polls, Image Polls | 5.5 | Medium | 2024-10-26 |
| CVE-2024-9585 | WordPress plugin Image Map Pro 安全漏洞 — Image Map Pro – Drag-and-drop Builder for Interactive Images | 6.4 | Medium | 2024-10-25 |
| CVE-2024-49378 | smartUp 跨站脚本漏洞 — smartup | 6.1 | - | 2024-10-25 |
| CVE-2024-10374 | WordPress plugin WP-Members Membership Plugin 跨站脚本漏洞 — WP-Members Membership Plugin | 6.4 | Medium | 2024-10-25 |
| CVE-2024-8666 | WordPress plugin Shoutcast Icecast HTML5 Radio Player 跨站脚本漏洞 — Shoutcast Icecast HTML5 Radio Player | 6.4 | Medium | 2024-10-25 |
| CVE-2024-10343 | WordPress plugin Beek Widget Extention 跨站脚本漏洞 — Beek Widget Extention | 6.4 | Medium | 2024-10-25 |
| CVE-2024-10112 | WordPress plugin Simple News 跨站脚本漏洞 — Simple News | 6.4 | Medium | 2024-10-25 |
| CVE-2024-10016 | WordPress plugin File Upload Types by WPForms 跨站脚本漏洞 — File Upload Types by WPForms | 6.4 | Medium | 2024-10-25 |
| CVE-2024-10150 | WordPress plugin Bamazoo – Button Generator 跨站脚本漏洞 — Bamazoo – Button Generator | 6.4 | Medium | 2024-10-25 |
| CVE-2024-10342 | WordPress plugin League of Legends Shortcodes 跨站脚本漏洞 — League of Legends Shortcodes | 6.4 | Medium | 2024-10-25 |
| CVE-2024-9607 | WordPress plugin 10Web Social Post Feed 跨站脚本漏洞 — 10Web Social Post Feed | 6.1 | Medium | 2024-10-25 |
| CVE-2024-10148 | WordPress plugin Awesome buttons 跨站脚本漏洞 — Awesome buttons | 6.4 | Medium | 2024-10-25 |
| CVE-2024-48870 | Sharp MFP 安全漏洞 — e-STUDIO 908 | 6.2 | Medium | 2024-10-25 |
| CVE-2024-47801 | Sharp MFP 安全漏洞 — Sharp Digital Full-color MFPs and Monochrome MFPs | 7.4 | High | 2024-10-25 |
| CVE-2024-10348 | SourceCodester Best House Rental Management System 跨站脚本漏洞 — Best House Rental Management System | 3.5 | Low | 2024-10-24 |
| CVE-2024-47882 | OpenRefine 安全漏洞 — OpenRefine | 5.9 | Medium | 2024-10-24 |
| CVE-2024-47880 | OpenRefine 安全漏洞 — OpenRefine | 8.1 | High | 2024-10-24 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21801 条 CVE 漏洞。