CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21852 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-24932 | WordPress Plugin VK Poster Group 跨站脚本漏洞 — VK Poster Group | 7.1 | High | 2024-02-12 |
| CVE-2024-24933 | WordPress Plugin Honeypot for WP Comment 跨站脚本漏洞 — Honeypot for WP Comment | 7.1 | High | 2024-02-12 |
| CVE-2023-51404 | WordPress Plugin My Agile Privacy 跨站脚本漏洞 — My Agile Privacy – The only GDPR solution for WordPress that you can truly trust | 6.5 | Medium | 2024-02-10 |
| CVE-2023-51415 | WordPress Plugin GiveWP 跨站脚本漏洞 — GiveWP – Donation Plugin and Fundraising Platform | 6.5 | Medium | 2024-02-10 |
| CVE-2023-51480 | WordPress Plugin Active Products Tables for WooCommerce 跨站脚本漏洞 — Active Products Tables for WooCommerce. Professional products tables for WooCommerce store | 6.5 | Medium | 2024-02-10 |
| CVE-2023-51485 | WordPress Plugin Pay with Vipps and MobilePay for WooCommerce 跨站脚本漏洞 — Pay with Vipps and MobilePay for WooCommerce | 6.5 | Medium | 2024-02-10 |
| CVE-2023-51488 | WordPress Plugin Crowdsignal Dashboard 跨站脚本漏洞 — Crowdsignal Dashboard – Polls, Surveys & more | 7.1 | High | 2024-02-10 |
| CVE-2023-51492 | WordPress Plugin If-So Dynamic Content Personalization 跨站脚本漏洞 — If-So Dynamic Content Personalization | 6.5 | Medium | 2024-02-10 |
| CVE-2023-51493 | WordPress Plugin Custom Post Carousels with Owl 跨站脚本漏洞 — Custom Post Carousels with Owl | 6.5 | Medium | 2024-02-10 |
| CVE-2024-23514 | WordPress Plugin Click To Tweet 跨站脚本漏洞 — Click To Tweet | 6.5 | Medium | 2024-02-10 |
| CVE-2024-23516 | WordPress Plugin CC BMI Calculator 跨站脚本漏洞 — CC BMI Calculator | 6.5 | Medium | 2024-02-10 |
| CVE-2024-23517 | WordPress Plugin Scheduling Plugin 跨站脚本漏洞 — Scheduling Plugin – Online Booking for WordPress | 6.5 | Medium | 2024-02-10 |
| CVE-2024-24712 | WordPress Plugin Heateor Social Login WordPress 跨站脚本漏洞 — Heateor Social Login WordPress | 6.5 | Medium | 2024-02-10 |
| CVE-2024-24713 | WordPress Plugin Auto Listings 跨站脚本漏洞 — Auto Listings – Car Listings & Car Dealership Plugin for WordPress | 6.5 | Medium | 2024-02-10 |
| CVE-2024-24717 | WordPress Plugin Beds24 Online Booking 跨站脚本漏洞 — Beds24 Online Booking | 5.9 | Medium | 2024-02-10 |
| CVE-2024-24801 | WordPress Plugin OWL Carousel 跨站脚本漏洞 — OWL Carousel – WordPress Owl Carousel Slider | 6.5 | Medium | 2024-02-10 |
| CVE-2024-24803 | WordPress Plugin Ultra Companion 跨站脚本漏洞 — Ultra Companion – Companion plugin for WPoperation Themes | 6.5 | Medium | 2024-02-10 |
| CVE-2024-24804 | WordPress Plugin MW WP Form 跨站脚本漏洞 — MW WP Form | 6.5 | Medium | 2024-02-10 |
| CVE-2024-24831 | WordPress Plugin Premium Addons for Elementor 跨站脚本漏洞 — Premium Addons for Elementor | 6.5 | Medium | 2024-02-10 |
| CVE-2024-25109 | ManageWiki 跨站脚本漏洞 — ManageWiki | 6.5 | Medium | 2024-02-09 |
| CVE-2024-0657 | WordPress Plugin Internal Link Juicer: SEO Auto Linker for WordPress 跨站脚本漏洞 — Internal Link Juicer: SEO Auto Linker for WordPress | 4.4 | Medium | 2024-02-09 |
| CVE-2024-25107 | WikiDiscover 跨站脚本漏洞 — WikiDiscover | 4.9 | Medium | 2024-02-08 |
| CVE-2023-51630 | Paessler PRTG Network Monitor 跨站脚本漏洞 — PRTG Network Monitor | 9.6 | - | 2024-02-08 |
| CVE-2024-24834 | WordPress Plugin BEAR 跨站脚本漏洞 — BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net | 5.9 | Medium | 2024-02-08 |
| CVE-2024-24836 | WordPress Plugin GDPR Data Request Form 跨站脚本漏洞 — GDPR Data Request Form | 6.5 | Medium | 2024-02-08 |
| CVE-2024-24871 | WordPress Plugin Blocksy 跨站脚本漏洞 — Blocksy | 6.5 | Medium | 2024-02-08 |
| CVE-2024-24877 | WordPress Plugin Wonder Slider Lite 跨站脚本漏洞 — Wonder Slider Lite | 7.1 | High | 2024-02-08 |
| CVE-2024-24878 | WordPress Plugin Portugal CTT Tracking for WooCommerce 跨站脚本漏洞 — Portugal CTT Tracking for WooCommerce | 7.1 | High | 2024-02-08 |
| CVE-2024-24879 | WordPress Plugin Link Library 安全漏洞 — Link Library | 7.1 | High | 2024-02-08 |
| CVE-2024-24880 | WordPress Plugin Apollo13 Framework Extensions 安全漏洞 — Apollo13 Framework Extensions | 6.5 | Medium | 2024-02-08 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21852 条 CVE 漏洞。