CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21807 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-22142 | WordPress Plugin Cozmoslabs Profile Builder Pro 跨站脚本漏洞 — Profile Builder Pro | 7.1 | High | 2024-01-12 |
| CVE-2024-0467 | Employee Profile Management System 跨站脚本漏洞 — Employee Profile Management System | 3.5 | Low | 2024-01-12 |
| CVE-2023-49260 | Hongdian Router H8951-4G-ESP 安全漏洞 — H8951-4G-ESP | 6.1 | - | 2024-01-12 |
| CVE-2023-49258 | Hongdian Router H8951-4G-ESP 安全漏洞 — H8951-4G-ESP | 6.1 | - | 2024-01-12 |
| CVE-2022-4960 | favorites-web 跨站脚本漏洞 — favorites-web | 3.5 | Low | 2024-01-12 |
| CVE-2022-4959 | qkmc-rk redbbs 跨站脚本漏洞 — redbbs | 3.5 | Low | 2024-01-11 |
| CVE-2024-0424 | CodeAstro Simple Banking System 跨站脚本漏洞 — Simple Banking System | 3.5 | Low | 2024-01-11 |
| CVE-2024-0423 | CodeAstro Online Food Ordering System 跨站脚本漏洞 — Online Food Ordering System | 3.5 | Low | 2024-01-11 |
| CVE-2024-0422 | Inventory Management System 跨站脚本漏洞 — POS and Inventory Management System | 3.5 | Low | 2024-01-11 |
| CVE-2023-5118 | Kofax Capture 跨站脚本漏洞 — Capture | 5.4 | Medium | 2024-01-11 |
| CVE-2023-6938 | WordPress Plugin Oxygen Builder 安全漏洞 — Oxygen Builder | 6.4 | Medium | 2024-01-11 |
| CVE-2022-4958 | qkmc-rk redbbs 跨站脚本漏洞 — redbbs | 3.5 | Low | 2024-01-11 |
| CVE-2023-4960 | WordPress Plugin WCFM Marketplace 安全漏洞 — WCFM Marketplace – Multivendor Marketplace for WooCommerce | 6.4 | Medium | 2024-01-11 |
| CVE-2023-7071 | WordPress Plugin Essential Blocks 安全漏洞 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | 6.4 | Medium | 2024-01-11 |
| CVE-2023-7070 | WordPress Plugin Email Encoder 安全漏洞 — Email Encoder – Protect Email Addresses and Phone Numbers | 6.4 | Medium | 2024-01-11 |
| CVE-2023-6561 | WordPress Plugin Featured Image from URL 安全漏洞 — Featured Image from URL (FIFU) | 6.4 | Medium | 2024-01-11 |
| CVE-2023-6737 | WordPress Plugin Enable Media Replace 安全漏洞 — Enable Media Replace | 4.7 | Medium | 2024-01-11 |
| CVE-2023-6782 | WordPress Plugin AMP for WP 安全漏洞 — AMP for WP – Accelerated Mobile Pages | 6.4 | Medium | 2024-01-11 |
| CVE-2023-6990 | WordPress Theme Weaver Xtreme 安全漏洞 — Weaver Xtreme | 5.4 | Medium | 2024-01-11 |
| CVE-2023-6645 | WordPress Plugin Post Grid Combo 安全漏洞 — Post Grid | 6.4 | Medium | 2024-01-11 |
| CVE-2023-6934 | WordPress Plugin Limit Login Attempts Reloaded 安全漏洞 — Limit Login Attempts Reloaded – Login Security, 2FA, Brute Force Protection & Firewall | 6.4 | Medium | 2024-01-11 |
| CVE-2023-6556 | WordPress Plugin FOX 安全漏洞 — FOX – Currency Switcher Professional for WooCommerce | 5.4 | Medium | 2024-01-11 |
| CVE-2023-6828 | WordPress Plugin Contact Form, Survey & Popup Form 安全漏洞 — Contact Form, Survey, Quiz & Popup Form Builder – ARForms | 7.2 | High | 2024-01-11 |
| CVE-2023-4962 | WordPress Plugin Video PopUp 安全漏洞 — Video PopUp | 6.4 | Medium | 2024-01-11 |
| CVE-2023-6994 | WordPress Plugin List category posts 安全漏洞 — List category posts | 6.4 | Medium | 2024-01-11 |
| CVE-2023-6776 | WordPress Plugin 3D FlipBook 安全漏洞 — 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery | 6.4 | Medium | 2024-01-11 |
| CVE-2023-6624 | WordPress Plugin Import and export users and customers 安全漏洞 — Import and export users and customers | 4.9 | Medium | 2024-01-11 |
| CVE-2023-6882 | WordPress Plugin Simple Membership 安全漏洞 — Simple Membership | 6.1 | Medium | 2024-01-11 |
| CVE-2023-6988 | WordPress Plugin Colibri Page Builder 安全漏洞 — Colibri Page Builder | 6.4 | Medium | 2024-01-11 |
| CVE-2023-4372 | WordPress Plugin LiteSpeed Cache 安全漏洞 — LiteSpeed Cache | 6.4 | Medium | 2024-01-11 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21807 条 CVE 漏洞。