CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21787 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-6428 | BigProf Online Invoicing System 跨站脚本漏洞 — Online Invoicing System | 6.3 | Medium | 2023-11-30 |
| CVE-2023-6427 | BigProf Online Invoicing System 安全漏洞 — Online Invoicing System | 6.3 | Medium | 2023-11-30 |
| CVE-2023-6426 | BigProf Online Invoicing System 跨站脚本漏洞 — Online Invoicing System | 6.3 | Medium | 2023-11-30 |
| CVE-2023-6425 | BigProf Online Clinic Management System 跨站脚本漏洞 — Online Clinic Management System | 6.3 | Medium | 2023-11-30 |
| CVE-2023-6424 | BigProf Online Clinic Management System 跨站脚本漏洞 — Online Clinic Management System | 6.3 | Medium | 2023-11-30 |
| CVE-2023-6423 | BigProf Online Clinic Management System 跨站脚本漏洞 — Online Clinic Management System | 6.3 | Medium | 2023-11-30 |
| CVE-2023-6422 | BigProf Online Clinic Management System 跨站脚本漏洞 — Online Clinic Management System | 6.3 | Medium | 2023-11-30 |
| CVE-2023-6027 | PHPMemcachedAdmin 跨站脚本漏洞 — PHPMemcachedAdmin | 6.1 | Medium | 2023-11-30 |
| CVE-2023-6420 | Voovi 跨站脚本漏洞 — Voovi Social Networking Script | 6.5 | Medium | 2023-11-30 |
| CVE-2023-6419 | Voovi 跨站脚本漏洞 — Voovi Social Networking Script | 6.5 | Medium | 2023-11-30 |
| CVE-2023-32291 | WordPress Plugin MonsterInsights 跨站脚本漏洞 — MonsterInsights Pro | 6.5 | Medium | 2023-11-30 |
| CVE-2023-38474 | WordPress Plugin Campaign Monitor for WordPress 跨站脚本漏洞 — Campaign Monitor for WordPress | 7.1 | High | 2023-11-30 |
| CVE-2023-40674 | WordPress Plugin Simple URLs 跨站脚本漏洞 — Simple URLs – Link Cloaking, Product Displays, and Affiliate Link Management | 6.5 | Medium | 2023-11-30 |
| CVE-2023-40680 | WordPress Plugin Yoast SEO 跨站脚本漏洞 — Yoast SEO | 5.9 | Medium | 2023-11-30 |
| CVE-2023-41127 | WordPress Plugin Evergreen Content Poster 跨站脚本漏洞 — Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media | 5.9 | Medium | 2023-11-30 |
| CVE-2023-41128 | WordPress Plugin WP Roadmap 跨站脚本漏洞 — WP Roadmap – Product Feedback Board | 5.9 | Medium | 2023-11-30 |
| CVE-2023-41136 | WordPress Plugin Simple Long Form 跨站脚本漏洞 — Simple Long Form | 5.9 | Medium | 2023-11-30 |
| CVE-2023-45050 | WordPress Plugin Jetpack 跨站脚本漏洞 — Jetpack – WP Security, Backup, Speed, & Growth | 6.5 | Medium | 2023-11-30 |
| CVE-2023-47505 | WordPress Plugin Elementor Website Builder 跨站脚本漏洞 — Elementor | 6.5 | Medium | 2023-11-30 |
| CVE-2023-47777 | WordPress Plugin WooCommerce 跨站脚本漏洞 — WooCommerce | 6.5 | Medium | 2023-11-30 |
| CVE-2023-47850 | WordPress Plugin Community by PeepSo 安全漏洞 — Community by PeepSo – Social Network, Membership, Registration, User Profiles | 6.5 | Medium | 2023-11-30 |
| CVE-2023-47851 | WordPress Plugin Bootstrap Shortcodes Ultimate 跨站脚本漏洞 — Bootstrap Shortcodes Ultimate | 6.5 | Medium | 2023-11-30 |
| CVE-2023-47854 | WordPress Plugin Parallax Image 跨站脚本漏洞 — Parallax Image | 6.5 | Medium | 2023-11-30 |
| CVE-2023-48289 | WordPress Plugin Import Spreadsheets from Microsoft Excel 跨站脚本漏洞 — Import Spreadsheets from Microsoft Excel | 6.5 | Medium | 2023-11-30 |
| CVE-2023-48322 | WordPress Plugin eDoc Employee Job Application 跨站脚本漏洞 — eDoc Employee Job Application – Best WordPress Job Manager for Employees | 7.1 | High | 2023-11-30 |
| CVE-2023-48326 | WordPress Plugin Events Manager 跨站脚本漏洞 — Events Manager | 7.1 | High | 2023-11-30 |
| CVE-2023-48329 | WordPress Plugin Fast Custom Social Share by CodeBard 跨站脚本漏洞 — Fast Custom Social Share by CodeBard | 5.9 | Medium | 2023-11-30 |
| CVE-2023-48336 | WordPress Plugin Easy Social Icons 跨站脚本漏洞 — Easy Social Icons | 6.5 | Medium | 2023-11-30 |
| CVE-2023-48737 | WordPress Plugin TriPay Payment Gateway 跨站脚本漏洞 — TriPay Payment Gateway | 5.9 | Medium | 2023-11-30 |
| CVE-2023-48743 | WordPress Plugin Simply Exclude 跨站脚本漏洞 — Simply Exclude | 5.8 | Medium | 2023-11-30 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21787 条 CVE 漏洞。