CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21877 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-4398 | WordPress plugin HTML5 Audio Player 安全漏洞 — HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player | 6.4 | Medium | 2024-05-10 |
| CVE-2024-4449 | WordPress plugin Essential Addons for Elementor 安全漏洞 — Essential Addons for Elementor – Popular Elementor Templates & Widgets | 6.4 | Medium | 2024-05-10 |
| CVE-2024-4448 | WordPress plugin Essential Addons for Elementor 安全漏洞 — Essential Addons for Elementor – Popular Elementor Templates & Widgets | 6.4 | Medium | 2024-05-10 |
| CVE-2024-4481 | WordPress plugin Gutenberg Blocks with AI by Kadence WP 安全漏洞 — Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | 6.4 | Medium | 2024-05-10 |
| CVE-2024-4688 | Campcodes Complete Web-Based School Management System 跨站脚本漏洞 — Complete Web-Based School Management System | 3.5 | Low | 2024-05-09 |
| CVE-2024-4687 | Campcodes Complete Web-Based School Management System 跨站脚本漏洞 — Complete Web-Based School Management System | 3.5 | Low | 2024-05-09 |
| CVE-2024-4686 | Campcodes Complete Web-Based School Management System 跨站脚本漏洞 — Complete Web-Based School Management System | 3.5 | Low | 2024-05-09 |
| CVE-2024-4104 | WordPress plugin ADFO 安全漏洞 — ADFO – Custom data in admin dashboard | 6.1 | Medium | 2024-05-09 |
| CVE-2024-2785 | WordPress plugin The Plus Addons for Elementor 安全漏洞 — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4193 | WordPress plugin Testimonial Slider 安全漏洞 — Testimonial Slider | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4567 | WordPress plugin Themify Shortcodes 安全漏洞 — Themify Shortcodes | 6.4 | Medium | 2024-05-09 |
| CVE-2024-0445 | WordPress plugin The Plus Addons for Elementor 安全漏洞 — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | 6.4 | Medium | 2024-05-09 |
| CVE-2024-2846 | WordPress plugin Visual Footer Credit Remover 安全漏洞 — Visual Footer Credit Remover | 4.4 | Medium | 2024-05-09 |
| CVE-2024-3923 | WordPress plugin Beaver Builder 安全漏洞 — Beaver Builder Page Builder – Drag and Drop Website Builder | 6.4 | Medium | 2024-05-09 |
| CVE-2024-3990 | WordPress plugin HT Mega 安全漏洞 — HT Mega Addons for Elementor – Elementor Widgets & Template Builder | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4335 | WordPress plugin Rank Math SEO with AI Best SEO Tools 安全漏洞 — Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | 6.4 | Medium | 2024-05-09 |
| CVE-2024-2923 | WordPress plugin Magical Addons For Elementor 安全漏洞 — Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4339 | WordPress plugin Prime Slider 安全漏洞 — Prime Slider – Addons for Elementor | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4411 | WordPress plugin Mihdan: Yandex Turbo Feed 安全漏洞 — Mihdan: Yandex Turbo Feed | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4446 | WordPress plugin Content Views 安全漏洞 — Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor) | 6.4 | Medium | 2024-05-09 |
| CVE-2024-3595 | WordPress plugin Pure Chat 安全漏洞 — Pure Chat – Live Chat & More! | 6.4 | Medium | 2024-05-09 |
| CVE-2024-3831 | WordPress plugin Enter Addons 安全漏洞 — Enter Addons – Ultimate Template Builder for Elementor | 6.4 | Medium | 2024-05-09 |
| CVE-2024-3916 | WordPress plugin Swift Framework 安全漏洞 — Swift Framework | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4383 | WordPress plugin Simple Membership 安全漏洞 — Simple Membership | 6.4 | Medium | 2024-05-09 |
| CVE-2024-3952 | WordPress plugin Advanced Ads 安全漏洞 — Advanced Ads – Ad Manager & AdSense | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4041 | WordPress plugin Yoast SEO 安全漏洞 — Yoast SEO – Advanced SEO with real-time guidance and built-in AI | 6.1 | Medium | 2024-05-09 |
| CVE-2024-1166 | WordPress plugin Image Hover Effects 安全漏洞 — Image Hover Effects – Elementor Addon | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4386 | WordPress plugin Gallery Block 安全漏洞 — Meow Gallery | 6.4 | Medium | 2024-05-09 |
| CVE-2024-3974 | WordPress plugin BuddyPress 安全漏洞 — BuddyPress | 6.4 | Medium | 2024-05-09 |
| CVE-2024-4316 | WordPress plugin EmbedPress 安全漏洞 — EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | 6.4 | Medium | 2024-05-09 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21877 条 CVE 漏洞。