CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21660 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-43698 | SICK APU 跨站脚本漏洞 — APU0200 | 7.1 | High | 2023-10-09 |
| CVE-2023-5452 | Snipe-IT 跨站脚本漏洞 — snipe/snipe-it | 5.4 | - | 2023-10-06 |
| CVE-2023-44390 | Mganss HtmlSanitizer 跨站脚本漏洞 — HtmlSanitizer | 6.1 | Medium | 2023-10-05 |
| CVE-2023-44389 | Zope 跨站脚本漏洞 — Zope | 3.1 | Low | 2023-10-04 |
| CVE-2023-42808 | Common Voice 跨站脚本漏洞 — common-voice | 6.1 | Medium | 2023-10-04 |
| CVE-2022-36277 | TCMAN GIM 跨站脚本漏洞 — GIM | 6.5 | Medium | 2023-10-04 |
| CVE-2023-40684 | IBM Content Navigator 跨站脚本漏洞 — Content Navigator | 4.6 | Medium | 2023-10-04 |
| CVE-2023-4497 | Chat Server 跨站脚本漏洞 — Easy Chat Server | 6.1 | Medium | 2023-10-04 |
| CVE-2023-4496 | Chat Server 跨站脚本漏洞 — Easy Chat Server | 6.1 | Medium | 2023-10-04 |
| CVE-2023-4495 | Chat Server 跨站脚本漏洞 — Easy Chat Server | 6.1 | Medium | 2023-10-04 |
| CVE-2023-4493 | Easy Address Book Web Server 跨站脚本漏洞 — Easy Address Book Web Server | 6.1 | Medium | 2023-10-04 |
| CVE-2023-4492 | Easy Address Book Web Server 跨站脚本漏洞 — Easy Address Book Web Server | 6.1 | Medium | 2023-10-04 |
| CVE-2023-4090 | WideStand CMS 跨站脚本漏洞 — Widestand CMS | 5.4 | Medium | 2023-10-04 |
| CVE-2023-5291 | WordPress Plugin Blog Filter 跨站脚本漏洞 — Blog Filter Post Filtering | 6.4 | Medium | 2023-10-04 |
| CVE-2023-5357 | WordPress Plugin Instagram 跨站脚本漏洞 — Instagram for WordPress | 6.4 | Medium | 2023-10-04 |
| CVE-2023-35905 | IBM FileNet Content Manager 跨站脚本漏洞 — FileNet Content Manager | 4.6 | Medium | 2023-10-04 |
| CVE-2023-4564 | Canopsis 跨站脚本漏洞 — Canopsis | 4.7 | Medium | 2023-10-03 |
| CVE-2023-3196 | Canopsis 跨站脚本漏洞 — Canopsis | 4.7 | Medium | 2023-10-03 |
| CVE-2023-32790 | NXLog 跨站脚本漏洞 — NXLog Manager | 4.6 | Medium | 2023-10-03 |
| CVE-2023-32671 | BuddyBoss Platform 跨站脚本漏洞 — BuddyBoss | 6.3 | Medium | 2023-10-03 |
| CVE-2023-32670 | BuddyBoss 跨站脚本漏洞 — BuddyBoss | 9.0 | Critical | 2023-10-03 |
| CVE-2023-5351 | SuiteCRM 跨站脚本漏洞 — salesagility/suitecrm | 5.4 | - | 2023-10-03 |
| CVE-2023-4100 | IDM Sistemas QSige 跨站脚本漏洞 — QSige | 6.5 | Medium | 2023-10-03 |
| CVE-2023-0828 | Artica Pandora FMS 跨站脚本漏洞 — Pandora FMS | 6.7 | Medium | 2023-10-03 |
| CVE-2023-5334 | WordPress Plugin Responsive header image slider 跨站脚本漏洞 — WP Responsive header image slider | 6.4 | Medium | 2023-10-03 |
| CVE-2023-44228 | WordPress Plugin Onclick show popup 跨站脚本漏洞 — Onclick show popup | 5.9 | Medium | 2023-10-02 |
| CVE-2023-44266 | WordPress Plugin WP Adminify 跨站脚本漏洞 — WP Adminify | 5.9 | Medium | 2023-10-02 |
| CVE-2023-44230 | WordPress Plugin Popup contact form 跨站脚本漏洞 — Popup contact form | 5.9 | Medium | 2023-10-02 |
| CVE-2023-44265 | WordPress Plugin Popup contact form 跨站脚本漏洞 — Popup contact form | 5.9 | Medium | 2023-10-02 |
| CVE-2023-44264 | WordPress Plugin The Awesome Feed – Custom Feed 跨站脚本漏洞 — The Awesome Feed – Custom Feed | 6.5 | Medium | 2023-10-02 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21660 条 CVE 漏洞。