CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21803 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-45592 | auditor-bundle 跨站脚本漏洞 — auditor-bundle | 8.2 | High | 2024-09-10 |
| CVE-2024-43800 | Express.js 跨站脚本漏洞 — serve-static | 5.0 | Medium | 2024-09-10 |
| CVE-2024-43799 | send 跨站脚本漏洞 — send | 5.0 | Medium | 2024-09-10 |
| CVE-2024-43796 | Express.js 跨站脚本漏洞 — express | 5.0 | Medium | 2024-09-10 |
| CVE-2024-6282 | WordPress plugin Master Addons 跨站脚本漏洞 — Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits | 5.4 | Medium | 2024-09-10 |
| CVE-2024-8241 | WordPress plugin Nova Blocks by Pixelgrade 跨站脚本漏洞 — Nova Blocks by Pixelgrade | 6.4 | Medium | 2024-09-10 |
| CVE-2024-8543 | WordPress plugin Slider comparison image before and after 跨站脚本漏洞 — Slider comparison image before and after | 6.4 | Medium | 2024-09-10 |
| CVE-2024-7618 | WordPress plugin Community by PeepSo – Social Network, Membership, Registration, User Profiles 安全漏洞 — Community by PeepSo – Download from PeepSo.com | 4.4 | Medium | 2024-09-10 |
| CVE-2024-7655 | WordPress plugin Community by PeepSo – Social Network, Membership, Registration, User Profiles 跨站脚本漏洞 — Community by PeepSo – Download from PeepSo.com | 4.4 | Medium | 2024-09-10 |
| CVE-2024-45280 | SAP NetWeaver AS 跨站脚本漏洞 — SAP NetWeaver AS Java (Logon Application) | 4.8 | Medium | 2024-09-10 |
| CVE-2024-45279 | SAP NetWeaver Application Server 跨站脚本漏洞 — SAP NetWeaver Application Server for ABAP (CRM Blueprint Application Builder Panel) | 6.1 | Medium | 2024-09-10 |
| CVE-2024-44120 | SAP NetWeaver Enterprise Portal 跨站脚本漏洞 — SAP NetWeaver Enterprise Portal | 4.7 | Medium | 2024-09-10 |
| CVE-2024-42378 | SAP S/4HANA 跨站脚本漏洞 — SAP S/4HANA eProcurement | 6.1 | Medium | 2024-09-10 |
| CVE-2024-8610 | SourceCodester Best House Rental Management System 跨站脚本漏洞 — Best House Rental Management System | 3.5 | Low | 2024-09-09 |
| CVE-2024-8605 | Inventory Management System 跨站脚本漏洞 — Inventory Management | 4.3 | Medium | 2024-09-09 |
| CVE-2024-8604 | Online Food Ordering System 跨站脚本漏洞 — Online Food Ordering System | 4.3 | Medium | 2024-09-09 |
| CVE-2024-40643 | Joplin 跨站脚本漏洞 — joplin | 9.7 | Critical | 2024-09-09 |
| CVE-2024-8583 | Bank Management System 跨站脚本漏洞 — Online Bank Management System | 3.5 | Low | 2024-09-08 |
| CVE-2024-8582 | Food Ordering Management System 跨站脚本漏洞 — Food Ordering Management System | 3.5 | Low | 2024-09-08 |
| CVE-2024-8572 | GoLang CMS 跨站脚本漏洞 — GoLang CMS | 3.5 | Low | 2024-09-08 |
| CVE-2024-8566 | Online Shop Store 跨站脚本漏洞 — Online Shop Store | 4.3 | Medium | 2024-09-07 |
| CVE-2024-8563 | PHP CRUD 跨站脚本漏洞 — PHP CRUD | 3.5 | Low | 2024-09-07 |
| CVE-2024-8562 | PHP CRUD 跨站脚本漏洞 — PHP CRUD | 3.5 | Low | 2024-09-07 |
| CVE-2024-8554 | SourceCodester Clinics Patient Management System 安全漏洞 — Clinics Patient Management System | 3.5 | Low | 2024-09-07 |
| CVE-2024-1596 | WordPress plugin Ninja Forms - File Uploads 跨站脚本漏洞 — Ninja Forms - File Uploads | 7.2 | High | 2024-09-07 |
| CVE-2024-6849 | WordPress plugin Preloader Plus 跨站脚本漏洞 — Preloader Plus – WordPress Loading Screen Plugin | 6.4 | Medium | 2024-09-07 |
| CVE-2024-8521 | Wavelog 跨站脚本漏洞 — Wavelog | 4.3 | Medium | 2024-09-07 |
| CVE-2024-38640 | QNAP Download Station 跨站脚本漏洞 — Download Station | 5.4 | - | 2024-09-06 |
| CVE-2024-32762 | QNAP QuLog Center 跨站脚本漏洞 — QuLog Center | 8.2 | High | 2024-09-06 |
| CVE-2024-27125 | QNAP Helpdesk 跨站脚本漏洞 — Helpdesk | 3.5 | Low | 2024-09-06 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21803 条 CVE 漏洞。