CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21853 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-3997 | WordPress plugin Prime Slider – Addons For Elementor 安全漏洞 — Prime Slider – Addons for Elementor | 6.4 | Medium | 2024-05-23 |
| CVE-2024-1815 | WordPress plugin Spectra 安全漏洞 — Spectra Gutenberg Blocks – Website Builder for the Block Editor | 6.4 | Medium | 2024-05-23 |
| CVE-2024-5165 | Eclipse Ditto 安全漏洞 — Eclipse Ditto | 6.5 | Medium | 2024-05-23 |
| CVE-2024-2861 | WordPress plugin ProfilePress 安全漏洞 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | 6.4 | Medium | 2024-05-23 |
| CVE-2024-4706 | WordPress plugin Microsoft Office 365 安全漏洞 — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) | 6.4 | Medium | 2024-05-23 |
| CVE-2024-3648 | WordPress plugin ShareThis Share Buttons 安全漏洞 — ShareThis Share Buttons | 6.4 | Medium | 2024-05-23 |
| CVE-2024-4043 | WordPress plugin WP Ultimate Post Grid 安全漏洞 — WP Ultimate Post Grid | 6.4 | Medium | 2024-05-23 |
| CVE-2024-4835 | GitLab CE/EE 安全漏洞 — GitLab | 8.0 | High | 2024-05-23 |
| CVE-2024-5177 | WordPress plugin Hash Elements 安全漏洞 — Hash Elements | 6.4 | Medium | 2024-05-23 |
| CVE-2024-4431 | WordPress plugin LA-Studio Element Kit for Elementor 安全漏洞 — LA-Studio Element Kit for Elementor | 6.4 | Medium | 2024-05-23 |
| CVE-2024-4895 | WordPress plugin wpDataTables 安全漏洞 — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin | 4.7 | Medium | 2024-05-23 |
| CVE-2024-3201 | WordPress plugin WP DSGVO Tools 安全漏洞 — WP DSGVO Tools (GDPR) | 6.4 | Medium | 2024-05-23 |
| CVE-2024-3065 | WordPress plugin PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode 安全漏洞 — PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode | 4.4 | Medium | 2024-05-23 |
| CVE-2024-4783 | WordPress plugin jQuery T(-) Countdown Widget 安全漏洞 — jQuery T(-) Countdown Widget | 6.4 | Medium | 2024-05-23 |
| CVE-2023-6844 | WordPress plugin iframe 安全漏洞 — iframe | 5.0 | Medium | 2024-05-23 |
| CVE-2024-4486 | WordPress plugin Awesome Contact Form7 for Elementor 安全漏洞 — Awesome Contact Form7 for Elementor | 6.4 | Medium | 2024-05-23 |
| CVE-2024-3926 | WordPress plugin Element Pack Elementor Addons 安全漏洞 — Element Pack – Widgets, Templates & Addons for Elementor | 6.4 | Medium | 2024-05-22 |
| CVE-2024-4262 | WordPress plugin Piotnet Addons For Elementor 安全漏洞 — Piotnet Addons For Elementor | 6.4 | Medium | 2024-05-22 |
| CVE-2024-5025 | WordPress plugin Memberpress 安全漏洞 — Memberpress | 6.4 | Medium | 2024-05-22 |
| CVE-2024-4362 | WordPress plugin SiteOrigin Widgets Bundle 安全漏洞 — SiteOrigin Widgets Bundle | 6.4 | Medium | 2024-05-22 |
| CVE-2024-4896 | WordPress plugin WPB Elementor Addons 安全漏洞 — WPB Addons for Elementor – News Ticker, Timeline, Team & More Widgets | 6.4 | Medium | 2024-05-22 |
| CVE-2024-2953 | WordPress plugin LuckyWP Table of Contents 安全漏洞 — LuckyWP Table of Contents | 5.5 | Medium | 2024-05-22 |
| CVE-2023-6487 | WordPress plugin LuckyWP Table of Contents 安全漏洞 — LuckyWP Table of Contents | 4.4 | Medium | 2024-05-22 |
| CVE-2024-2119 | WordPress plugin LuckyWP Table of Contents 安全漏洞 — LuckyWP Table of Contents | 6.1 | Medium | 2024-05-22 |
| CVE-2024-0632 | WordPress plugin Automatic Translator with Google Translate 安全漏洞 — Automatic Translator with Google Translate | 4.4 | Medium | 2024-05-22 |
| CVE-2024-2163 | WordPress plugin Ninja Beaver Add-ons for Beaver Builder 安全漏洞 — Ninja Beaver Add-ons for Beaver Builder | 6.4 | Medium | 2024-05-22 |
| CVE-2024-3671 | WordPress plugin Print-O-Matic 安全漏洞 — Print-O-Matic | 6.4 | Medium | 2024-05-22 |
| CVE-2024-1762 | WordPress plugin NextScripts Social Networks Auto-Poster 跨站脚本漏洞 — NextScripts: Social Networks Auto-Poster | 6.1 | Medium | 2024-05-22 |
| CVE-2024-3198 | WordPress plugin WP Font Awesome Share Icons 安全漏洞 — WP Font Awesome Share Icons | 6.4 | Medium | 2024-05-22 |
| CVE-2024-3066 | WordPress Plugin Elegant Addons for elementor 安全漏洞 — Elegant Addons for elementor | 6.4 | Medium | 2024-05-22 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21853 条 CVE 漏洞。