CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21766 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-47544 | WordPress Plugin Visual Website Collaboration, Feedback & Project Management – Atarim 安全漏洞 — Visual Website Collaboration, Feedback & Project Management – Atarim | 7.1 | High | 2023-11-14 |
| CVE-2023-47545 | WordPress Plugin Forms for Mailchimp by Optin Cat – Grow Your MailChimp List 安全漏洞 — Forms for Mailchimp by Optin Cat – Grow Your MailChimp List | 5.9 | Medium | 2023-11-14 |
| CVE-2023-47546 | WordPress Plugin OneClick Chat to Order 安全漏洞 — OneClick Chat to Order | 5.9 | Medium | 2023-11-14 |
| CVE-2023-47547 | WordPress Plugin Products, Order & Customers Export for WooCommerce安全漏洞 — Products, Order & Customers Export for WooCommerce | 7.1 | High | 2023-11-14 |
| CVE-2023-47549 | WordPress Plugin EazyDocs 安全漏洞 — EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin (easy docs, knowledgebase) | 6.8 | Medium | 2023-11-14 |
| CVE-2023-36007 | Microsoft Dynamics 365 安全漏洞 — Send Customer Voice survey from Dynamics 365 app | 7.6 | High | 2023-11-14 |
| CVE-2023-47125 | TYPO3 安全漏洞 — html-sanitizer | 4.7 | Medium | 2023-11-14 |
| CVE-2023-47554 | WordPress Plugin Actueel Financieel Nieuws – Denk Internet Solutions 安全漏洞 — Actueel Financieel Nieuws – Denk Internet Solutions | 5.9 | Medium | 2023-11-14 |
| CVE-2023-47646 | WordPress Plugin Recently viewed and most viewed products 安全漏洞 — Recently viewed and most viewed products | 5.9 | Medium | 2023-11-14 |
| CVE-2023-47653 | WordPress Plugin TWB Woocommerce Reviews 安全漏洞 — TWB Woocommerce Reviews | 5.9 | Medium | 2023-11-14 |
| CVE-2023-47654 | WordPress Plugin BZScore – Live Score 安全漏洞 — BZScore – Live Score | 6.5 | Medium | 2023-11-14 |
| CVE-2023-47656 | WordPress Plugin ANAC XML Bandi di Gara 安全漏洞 — ANAC XML Bandi di Gara | 5.9 | Medium | 2023-11-14 |
| CVE-2023-47658 | WordPress Plugin Extra Product Options for WooCommerce 安全漏洞 — Extra Product Options for WooCommerce | 5.9 | Medium | 2023-11-14 |
| CVE-2023-36016 | Microsoft Dynamics 365 安全漏洞 — Microsoft Dynamics 365 (on-premises) version 9.0 | 6.2 | Medium | 2023-11-14 |
| CVE-2023-36031 | Microsoft Dynamics 365 安全漏洞 — Microsoft Dynamics 365 (on-premises) version 9.1 | 7.6 | High | 2023-11-14 |
| CVE-2023-36030 | Microsoft Dynamics 365 安全漏洞 — Microsoft Dynamics 365 (on-premises) version 9.1 | 6.1 | Medium | 2023-11-14 |
| CVE-2023-36410 | Microsoft Dynamics 365 安全漏洞 — Microsoft Dynamics 365 (on-premises) version 9.1 | 7.6 | High | 2023-11-14 |
| CVE-2023-47659 | WordPress Plugin Lava Directory Manager 安全漏洞 — Lava Directory Manager | 6.5 | Medium | 2023-11-14 |
| CVE-2023-47660 | WordPress Plugin Product Visibility by Country for WooCommerce 安全漏洞 — Product Visibility by Country for WooCommerce | 5.9 | Medium | 2023-11-14 |
| CVE-2023-6128 | SuiteCRM 安全漏洞 — salesagility/suitecrm | 5.4 | - | 2023-11-14 |
| CVE-2023-46099 | Siemens SIMATIC PCS 安全漏洞 — SIMATIC PCS neo | 5.4 | Medium | 2023-11-14 |
| CVE-2023-47657 | WordPress Plugin Direct Checkout – Quick View – Buy Now For WooCommerce 安全漏洞 — Direct Checkout – Quick View – Buy Now For WooCommerce | 5.9 | Medium | 2023-11-13 |
| CVE-2023-47662 | WordPress Plugin Live Gold Price & Silver Price Charts Widgets 跨站脚本漏洞 — Live Gold Price & Silver Price Charts Widgets | 5.9 | Medium | 2023-11-13 |
| CVE-2023-47665 | WordPress Plugin Plainview Protect Passwords 安全漏洞 — Plainview Protect Passwords | 7.1 | High | 2023-11-13 |
| CVE-2023-47673 | WordPress Plugin Post Pay Counter 安全漏洞 — Post Pay Counter | 7.1 | High | 2023-11-13 |
| CVE-2023-47680 | WordPress Plugin Qi Addons For Elementor 安全漏洞 — Qi Addons For Elementor | 6.5 | Medium | 2023-11-13 |
| CVE-2023-47684 | WordPress Plugin essential-grid 跨站脚本漏洞 — Essential Grid | 7.1 | High | 2023-11-13 |
| CVE-2023-47690 | WordPress Plugin Additional Order Filters for WooCommerce 安全漏洞 — Additional Order Filters for WooCommerce | 7.1 | High | 2023-11-13 |
| CVE-2023-47695 | WordPress Plugin Shortcodes Finder 安全漏洞 — Shortcodes Finder | 7.1 | High | 2023-11-13 |
| CVE-2023-47696 | WordPress Plugin Product Enquiry for WooCommerce 安全漏洞 — Product Enquiry for WooCommerce | 7.1 | High | 2023-11-13 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21766 条 CVE 漏洞。