CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21813 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-6050 | SOKRATES-software SOWA OPAC 安全漏洞 — SOWA OPAC | 6.1AI | MediumAI | 2024-07-01 |
| CVE-2023-50964 | IBM InfoSphere Information Server 跨站脚本漏洞 — InfoSphere Information Server | 5.4 | Medium | 2024-06-30 |
| CVE-2024-28794 | IBM InfoSphere Information Server 安全漏洞 — InfoSphere Information Server | 5.4 | Medium | 2024-06-30 |
| CVE-2024-28797 | IBM InfoSphere Information Server 安全漏洞 — InfoSphere Information Server | 6.4 | Medium | 2024-06-30 |
| CVE-2024-28798 | IBM InfoSphere Information Server 跨站脚本漏洞 — InfoSphere Information Server | 7.2 | High | 2024-06-30 |
| CVE-2024-28795 | IBM InfoSphere Information Server 跨站脚本漏洞 — InfoSphere Information Server | 5.4 | Medium | 2024-06-30 |
| CVE-2024-5062 | ZenML 跨站脚本漏洞 — zenml-io/zenml | 6.1AI | MediumAI | 2024-06-30 |
| CVE-2024-6415 | Ingenico Estate Manager 跨站脚本漏洞 — Estate Manager | 2.4 | Low | 2024-06-30 |
| CVE-2023-4017 | WordPress Plugin Goya 安全漏洞 — Goya | 6.1 | Medium | 2024-06-29 |
| CVE-2024-5819 | WordPress plugin Page Builder Features 安全漏洞 — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | 6.4 | Medium | 2024-06-29 |
| CVE-2024-5790 | WordPress plugin Happy Addons for Elementor 安全漏洞 — Happy Addons for Elementor | 6.4 | Medium | 2024-06-29 |
| CVE-2024-5666 | WordPress plugin Extensions for Elementor 安全漏洞 — Extensions for Elementor | 6.4 | Medium | 2024-06-29 |
| CVE-2024-6363 | WordPress plugin Stock Ticker 安全漏洞 — Stock Ticker | 6.4 | Medium | 2024-06-29 |
| CVE-2024-5889 | WordPress plugin Events Manager 安全漏洞 — Events Manager – Calendar, Bookings, Tickets, and more! | 6.1 | Medium | 2024-06-29 |
| CVE-2024-5192 | WordPress plugin Funnel Builder for WordPress by FunnelKit 安全漏洞 — FunnelKit – Funnel Builder for WooCommerce Checkout | 6.4 | Medium | 2024-06-29 |
| CVE-2024-39307 | kavita 安全漏洞 — Kavita | 3.5 | Low | 2024-06-28 |
| CVE-2024-25041 | IBM Cognos Analytics 跨站脚本漏洞 — Cognos Analytics | 5.4 | Medium | 2024-06-28 |
| CVE-2024-38521 | Hush Line 安全漏洞 — hushline | 8.8 | High | 2024-06-28 |
| CVE-2024-3801 | Concept Intermedia S@M CMS 安全漏洞 — S@M CMS | 6.1AI | MediumAI | 2024-06-28 |
| CVE-2024-3800 | Concept Intermedia S@M CMS 安全漏洞 — S@M CMS | 6.1AI | MediumAI | 2024-06-28 |
| CVE-2024-5737 | Joomla! Admiror Frames 安全漏洞 — AdmirorFrames | 6.1AI | MediumAI | 2024-06-28 |
| CVE-2024-5922 | WordPress plugin Scylla 安全漏洞 — Scylla lite | 6.4 | Medium | 2024-06-28 |
| CVE-2024-5925 | WordPress plugin Theron 安全漏洞 — Theron Lite | 6.4 | Medium | 2024-06-28 |
| CVE-2024-5662 | WordPress plugin Ultimate Post Kit Addons For Elementor 安全漏洞 — Ultimate Post Kit Addons for Elementor | 6.4 | Medium | 2024-06-28 |
| CVE-2024-5424 | WordPress plugin Gallery Blocks with Lightbox 安全漏洞 — Mixed Media Gallery Blocks | 6.4 | Medium | 2024-06-28 |
| CVE-2024-6288 | WordPress plugin Conversios 安全漏洞 — Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels | 4.7 | Medium | 2024-06-28 |
| CVE-2024-5796 | WordPress plugin Infinite 安全漏洞 — Infinite | 6.4 | Medium | 2024-06-28 |
| CVE-2024-5788 | WordPress plugin Silesia 安全漏洞 — Silesia | 6.4 | Medium | 2024-06-28 |
| CVE-2024-6296 | WordPress plugin Stackable 安全漏洞 — Stackable – Page Builder Gutenberg Blocks | 6.4 | Medium | 2024-06-28 |
| CVE-2024-5933 | LoLLMs 跨站脚本漏洞 — parisneo/lollms-webui | 6.1AI | MediumAI | 2024-06-27 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21813 条 CVE 漏洞。