CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21658 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-3840 | NxFilter 跨站脚本漏洞 — NxFilter | 3.5 | Low | 2023-07-23 |
| CVE-2023-3838 | DedeBIZ 跨站脚本漏洞 — DedeBIZ | 2.4 | Low | 2023-07-23 |
| CVE-2023-3837 | DedeBIZ 跨站脚本漏洞 — DedeBIZ | 2.4 | Low | 2023-07-22 |
| CVE-2023-3835 | Bug Finder MineStack 跨站脚本漏洞 — MineStack | 3.5 | Low | 2023-07-22 |
| CVE-2023-3834 | Bug Finder EX-RATE 跨站脚本漏洞 — EX-RATE | 3.5 | Low | 2023-07-22 |
| CVE-2023-3833 | Bug Finder Montage 跨站脚本漏洞 — Montage | 3.5 | Low | 2023-07-22 |
| CVE-2023-3832 | Bug Finder Wedding Wonders 跨站脚本漏洞 — Wedding Wonders | 3.5 | Low | 2023-07-22 |
| CVE-2023-3831 | Bug Finder SASS BILLER 跨站脚本漏洞 — Finounce | 3.5 | Low | 2023-07-22 |
| CVE-2023-3830 | Bug Finder SASS BILLER 跨站脚本漏洞 — SASS BILLER | 3.5 | Low | 2023-07-22 |
| CVE-2023-3829 | Bug Finder ICOGenie 跨站脚本漏洞 — ICOGenie | 3.5 | Low | 2023-07-22 |
| CVE-2023-3828 | Bug Finder Listplace 跨站脚本漏洞 — Listplace Directory Listing Platform | 3.5 | Low | 2023-07-22 |
| CVE-2023-3827 | Bug Finder Listplace 跨站脚本漏洞 — Listplace Directory Listing Platform | 3.5 | Low | 2023-07-22 |
| CVE-2023-28530 | IBM Cognos Analytics 跨站脚本漏洞 — Cognos Analytics | 5.4 | Medium | 2023-07-22 |
| CVE-2023-25929 | IBM Cognos Analytics 跨站脚本漏洞 — Cognos Analytics | 4.6 | Medium | 2023-07-22 |
| CVE-2023-37905 | CKEditor 跨站脚本漏洞 — CKEditor-WordCount-Plugin | 6.1 | Medium | 2023-07-21 |
| CVE-2023-25841 | Esri ArcGIS Server 跨站脚本漏洞 — ArcGIS Enterprise Server | 6.1 | Medium | 2023-07-21 |
| CVE-2023-25840 | Esri ArcGIS Server 跨站脚本漏洞 — ArcGIS Enterprise Server | 3.4 | Low | 2023-07-21 |
| CVE-2023-37901 | Adrian indico 跨站脚本漏洞 — indico | 5.4 | Medium | 2023-07-21 |
| CVE-2023-3822 | Pimcore 跨站脚本漏洞 — pimcore/pimcore | 5.4 | - | 2023-07-21 |
| CVE-2023-3821 | Pimcore 跨站脚本漏洞 — pimcore/pimcore | 5.4 | - | 2023-07-21 |
| CVE-2023-3815 | RuoYi 跨站脚本漏洞 — RuoYi | 3.5 | Low | 2023-07-21 |
| CVE-2023-25837 | Esri ArcGIS Enterprise 跨站脚本漏洞 — Portal for ArcGIS Sites | 8.4 | High | 2023-07-21 |
| CVE-2023-25836 | Esri Portal For ArcGIS 跨站脚本漏洞 — Portal for ArcGIS Sites | 5.4 | Medium | 2023-07-21 |
| CVE-2023-25835 | Esri Portal For ArcGIS 跨站脚本漏洞 — Portal for ArcGIS Sites | 8.4 | High | 2023-07-20 |
| CVE-2023-3794 | Bug Finder ChainCity Real Estate Investment Platform 跨站脚本漏洞 — ChainCity Real Estate Investment Platform | 3.5 | Low | 2023-07-20 |
| CVE-2023-3790 | Boom CMS 跨站脚本漏洞 — CMS | 3.5 | Low | 2023-07-20 |
| CVE-2023-3789 | PaulPrinting CMS 跨站脚本漏洞 — CMS | 3.5 | Low | 2023-07-20 |
| CVE-2023-3788 | Active IT zone Active Super Shop CMS 跨站脚本漏洞 — Active Super Shop CMS | 3.5 | Low | 2023-07-20 |
| CVE-2023-3787 | Tiva Events Calender 跨站脚本漏洞 — Tiva Events Calender | 3.5 | Low | 2023-07-20 |
| CVE-2023-3785 | PaulPrinting CMS 跨站脚本漏洞 — CMS | 3.5 | Low | 2023-07-20 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21658 条 CVE 漏洞。