CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21809 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-3603 | WordPress plugin OSM – OpenStreetMap 安全漏洞 — OSM – OpenStreetMap | 6.4 | Medium | 2024-07-09 |
| CVE-2024-4868 | WordPress plugin Extensions for Elementor 安全漏洞 — Extensions for Elementor | 6.4 | Medium | 2024-07-09 |
| CVE-2024-5479 | WordPress plugin Easy Pixels 安全漏洞 — Easy Pixels | 7.2 | High | 2024-07-09 |
| CVE-2024-5881 | WordPress plugin Webico Slider Flatsome Addons 安全漏洞 — Webico Slider Flatsome Addons | 6.4 | Medium | 2024-07-09 |
| CVE-2024-6170 | WordPress Plugin Unlimited Elements For Elementor 安全漏洞 — Unlimited Elements For Elementor | 6.4 | Medium | 2024-07-09 |
| CVE-2024-6169 | WordPress Plugin Unlimited Elements For Elementor 安全漏洞 — Unlimited Elements For Elementor | 6.4 | Medium | 2024-07-09 |
| CVE-2024-4667 | WordPress plugin Blog, Posts and Category Filter for Elementor 安全漏洞 — Blog, Posts and Category Filter for Elementor | 6.4 | Medium | 2024-07-09 |
| CVE-2024-39595 | SAP Business Warehouse 跨站脚本漏洞 — SAP Business Warehouse - Business Planning and Simulation | 5.4 | Medium | 2024-07-09 |
| CVE-2024-39594 | SAP Business Warehouse 跨站脚本漏洞 — SAP Business Warehouse - Business Planning and Simulation | 6.1 | Medium | 2024-07-09 |
| CVE-2024-37174 | SAP CRM 跨站脚本漏洞 — SAP CRM WebClient UI | 6.1 | Medium | 2024-07-09 |
| CVE-2024-37173 | SAP CRM 跨站脚本漏洞 — SAP CRM WebClient UI | 6.1 | Medium | 2024-07-09 |
| CVE-2024-34685 | SAP NetWeaver 跨站脚本漏洞 — SAP NetWeaver Knowledge Management XMLEditor | 6.1 | Medium | 2024-07-09 |
| CVE-2024-39308 | RailsAdmin 安全漏洞 — rails_admin | 6.1AI | MediumAI | 2024-07-08 |
| CVE-2024-37389 | Apache NiFi 安全漏洞 — Apache NiFi | 4.6 | Medium | 2024-07-08 |
| CVE-2024-37528 | IBM Cloud Pak for Business Automation 跨站脚本漏洞 — Cloud Pak for Business Automation | 4.8 | Medium | 2024-07-08 |
| CVE-2024-5711 | Devika 跨站脚本漏洞 — stitionai/devika | 5.4 | - | 2024-07-08 |
| CVE-2024-6539 | SpringBootCMS 跨站脚本漏洞 — SpringBootCMS | 3.5 | Low | 2024-07-07 |
| CVE-2024-6229 | Quivr 跨站脚本漏洞 — stangirard/quivr | 5.4AI | MediumAI | 2024-07-07 |
| CVE-2024-37554 | WordPress plugin UltraAddons Elementor Lite 跨站脚本漏洞 — UltraAddons Elementor Lite | 6.5 | Medium | 2024-07-06 |
| CVE-2024-37553 | WordPress plugin Testimonials Widget 跨站脚本漏洞 — Testimonials Widget | 6.5 | Medium | 2024-07-06 |
| CVE-2024-37546 | WordPress plugin Image Hover Effects with Carousel 安全漏洞 — Image Hover Effects - Caption Hover with Carousel | 6.5 | Medium | 2024-07-06 |
| CVE-2024-37541 | WordPress plugin Elementor Addons, Widgets and Enhancements – Stax 跨站脚本漏洞 — Elementor Addons, Widgets and Enhancements – Stax | 6.5 | Medium | 2024-07-06 |
| CVE-2024-37539 | WordPress plugin WP To Do 安全漏洞 — WP To Do | 6.5 | Medium | 2024-07-06 |
| CVE-2024-6526 | Ecommerce-CodeIgniter-Bootstrap 跨站脚本漏洞 — Ecommerce-CodeIgniter-Bootstrap | 3.5 | Low | 2024-07-05 |
| CVE-2024-6523 | Zkteco BioTime 安全漏洞 — BioTime | 3.5 | Low | 2024-07-05 |
| CVE-2024-6511 | RuoYi 跨站脚本漏洞 — RuoYi | 3.5 | Low | 2024-07-04 |
| CVE-2024-37472 | WordPress plugin Woffice 安全漏洞 — Woffice | 7.1 | High | 2024-07-04 |
| CVE-2024-3639 | WordPress plugin Elementor Addons by Livemesh 安全漏洞 — Livemesh Addons by Elementor | 6.4 | Medium | 2024-07-04 |
| CVE-2024-2926 | WordPress plugin Elementor Addons by Livemesh 安全漏洞 — Livemesh Addons by Elementor | 6.4 | Medium | 2024-07-04 |
| CVE-2024-3638 | WordPress plugin Elementor Addons by Livemesh 安全漏洞 — Livemesh Addons by Elementor | 6.4 | Medium | 2024-07-04 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21809 条 CVE 漏洞。