CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21807 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-43413 | Xibo CMS 安全漏洞 — xibo-cms | 3.5 | Low | 2024-09-03 |
| CVE-2024-43412 | Xibo CMS 安全漏洞 — xibo-cms | 4.6 | Medium | 2024-09-03 |
| CVE-2024-7654 | Progress Software OpenEdge 安全漏洞 — OpenEdge | 8.3 | High | 2024-09-03 |
| CVE-2024-42061 | Zyxel多款产品 跨站脚本漏洞 — ATP series firmware | 6.1 | Medium | 2024-09-03 |
| CVE-2024-43792 | Halo 安全漏洞 — halo | 6.3 | Medium | 2024-09-02 |
| CVE-2024-28100 | eLabFTW 安全漏洞 — elabftw | 8.9 | High | 2024-09-02 |
| CVE-2024-6920 | NAC Telecommunication NACPremium 跨站脚本漏洞 — NACPremium | 5.4AI | MediumAI | 2024-09-02 |
| CVE-2024-8004 | Dassault Systèmes 3DEXPERIENCE 安全漏洞 — ENOVIA Collaborative Industry Innovator | 8.7 | High | 2024-09-02 |
| CVE-2024-7939 | Dassault Systèmes 3DEXPERIENCE 安全漏洞 — 3DSwymer | 8.7 | High | 2024-09-02 |
| CVE-2024-7938 | Dassault Systèmes 3DEXPERIENCE 安全漏洞 — 3DSwymer | 8.7 | High | 2024-09-02 |
| CVE-2024-7932 | Dassault Systèmes 3DEXPERIENCE 安全漏洞 — 3DSwymer | 8.7 | High | 2024-09-02 |
| CVE-2024-38858 | Checkmk 安全漏洞 — Checkmk | 9.0AI | CriticalAI | 2024-09-02 |
| CVE-2024-8370 | Grocy 跨站脚本漏洞 — Grocy | 3.5 | Low | 2024-09-01 |
| CVE-2024-8366 | Code-Projects Pharmacy Management System 跨站脚本漏洞 — Pharmacy Management System | 4.3 | Medium | 2024-08-31 |
| CVE-2024-8108 | WordPress plugin Share This Image 跨站脚本漏洞 — Share This Image | 6.4 | Medium | 2024-08-31 |
| CVE-2024-8276 | WordPress plugin WPZOOM Portfolio Lite 跨站脚本漏洞 — WPZOOM Portfolio Lite – Filterable Portfolio Plugin | 6.4 | Medium | 2024-08-31 |
| CVE-2024-3886 | WordPress plugin tagDiv Composer 跨站脚本漏洞 — tagDiv Composer | 6.1 | Medium | 2024-08-31 |
| CVE-2024-5212 | WordPress plugin tagDiv Composer 跨站脚本漏洞 — tagDiv Composer | 6.1 | Medium | 2024-08-31 |
| CVE-2024-6585 | Lightdash 跨站脚本漏洞 — Lightdash | 5.4 | - | 2024-08-30 |
| CVE-2024-45047 | Svelte 跨站脚本漏洞 — svelte | 5.4 | Medium | 2024-08-30 |
| CVE-2024-8337 | SourceCodester Contact Manager with Export to VCF 跨站脚本漏洞 — Contact Manager with Export to VCF | 3.5 | Low | 2024-08-30 |
| CVE-2024-8274 | WordPress plugin WP Booking Calendar 跨站脚本漏洞 — Booking Calendar | 6.1 | Medium | 2024-08-30 |
| CVE-2024-7122 | WordPress plugin Elementor Addon Elements 跨站脚本漏洞 — Addon Elements for Elementor (formerly Elementor Addon Elements) | 6.4 | Medium | 2024-08-30 |
| CVE-2024-34577 | ELECOM多款产品 安全漏洞 — WRC-X3000GS2-B | 6.1AI | MediumAI | 2024-08-30 |
| CVE-2024-42412 | ELECOM多款产品 安全漏洞 — WAB-I1750-PS | 6.1AI | MediumAI | 2024-08-30 |
| CVE-2024-5879 | WordPress plugin HubSpot 跨站脚本漏洞 — HubSpot All-In-One Marketing – Forms, Popups, Live Chat | 6.4 | Medium | 2024-08-30 |
| CVE-2024-3998 | WordPress plugin Betheme 跨站脚本漏洞 — Betheme | 6.4 | Medium | 2024-08-30 |
| CVE-2024-4401 | WordPress plugin Elementor Addon Elements 跨站脚本漏洞 — Addon Elements for Elementor (formerly Elementor Addon Elements) | 6.4 | Medium | 2024-08-30 |
| CVE-2024-5024 | WordPress plugin Memberpress 跨站脚本漏洞 — Memberpress | 6.1 | Medium | 2024-08-30 |
| CVE-2024-5061 | WordPress plugin Enfold 跨站脚本漏洞 — Enfold - Responsive Multi-Purpose Theme | 6.4 | Medium | 2024-08-30 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21807 条 CVE 漏洞。