CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21615 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-3167 | WordPress Plugin Mail Queue 跨站脚本漏洞 — Mail Queue | 7.2 | High | 2023-07-12 |
| CVE-2023-3166 | WordPress Plugin Lana Email Logger 跨站脚本漏洞 — Lana Email Logger | 7.2 | High | 2023-07-12 |
| CVE-2023-3369 | WordPress Plugin About Me 3000 widget 跨站脚本漏洞 — About Me 3000 widget | 4.4 | Medium | 2023-07-12 |
| CVE-2023-3092 | WordPress Plugin SMTP Mail 跨站脚本漏洞 — SMTP Mail | 7.2 | High | 2023-07-12 |
| CVE-2023-3088 | WordPress Plugin WP Mail Log 跨站脚本漏洞 — WP Mail Log | 7.2 | High | 2023-07-12 |
| CVE-2023-3158 | WordPress Plugin Mail Control 跨站脚本漏洞 — Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking | 7.2 | High | 2023-07-12 |
| CVE-2023-3082 | WordPress Plugin Post SMTP 跨站脚本漏洞 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | 7.2 | High | 2023-07-12 |
| CVE-2023-3168 | WordPress Plugin WP Reroute Email 跨站脚本漏洞 — WP Reroute Email | 7.2 | High | 2023-07-12 |
| CVE-2023-3093 | WordPress Plugin YaySMTP 跨站脚本漏洞 — YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service | 7.2 | High | 2023-07-12 |
| CVE-2023-3135 | WordPress Plugin Mailtree Log Mail 跨站脚本漏洞 — Mailtree Log Mail | 7.2 | High | 2023-07-12 |
| CVE-2023-3080 | WordPress Plugin WP Mail Catcher 跨站脚本漏洞 — Mail logging – WP Mail Catcher | 7.2 | High | 2023-07-12 |
| CVE-2023-3122 | WordPress Plugin GD Mail Queue 跨站脚本漏洞 — GD Mail Queue | 7.2 | High | 2023-07-12 |
| CVE-2023-23756 | Joomla 跨站脚本漏洞 — oneVote component for Joomla | 6.1 | - | 2023-07-11 |
| CVE-2023-37280 | Pimcore 跨站脚本漏洞 — admin-ui-classic-bundle | 5.0 | Medium | 2023-07-11 |
| CVE-2023-34089 | Decidim 跨站脚本漏洞 — decidim | 8.1 | High | 2023-07-11 |
| CVE-2023-32693 | Decidim 跨站脚本漏洞 — decidim | 8.1 | High | 2023-07-11 |
| CVE-2023-35335 | Microsoft Dynamics 365 跨站脚本漏洞 — Microsoft Dynamics 365 (on-premises) version 9.0 | 8.2 | High | 2023-07-11 |
| CVE-2023-33171 | Microsoft Dynamics 365 跨站脚本漏洞 — Microsoft Dynamics 365 (on-premises) version 9.0 | 8.2 | High | 2023-07-11 |
| CVE-2023-33159 | Microsoft SharePoint 安全漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2023-07-11 |
| CVE-2023-29347 | Microsoft Windows Admin Center 安全漏洞 — Windows Admin Center | 8.7 | High | 2023-07-11 |
| CVE-2023-3620 | tarteaucitron.js 跨站脚本漏洞 — amauric/tarteaucitron.js | 5.4 | - | 2023-07-11 |
| CVE-2023-36390 | Siemens RUGGEDCOM ROX 系列多款产品 跨站脚本漏洞 — RUGGEDCOM ROX MX5000 | 8.8 | High | 2023-07-11 |
| CVE-2023-36389 | Siemens RUGGEDCOM ROX 跨站脚本漏洞 — RUGGEDCOM ROX MX5000 | 8.8 | High | 2023-07-11 |
| CVE-2023-36386 | Siemens RUGGEDCOM ROX 系列多款产品 跨站脚本漏洞 — RUGGEDCOM ROX MX5000 | 8.8 | High | 2023-07-11 |
| CVE-2023-36918 | SAP Enable Now 跨站脚本漏洞 — SAP Enable Now | 6.1 | Medium | 2023-07-11 |
| CVE-2023-33988 | SAP Enable Now 跨站脚本漏洞 — SAP Enable Now | 6.1 | Medium | 2023-07-11 |
| CVE-2023-24488 | Citrix Systems Citrix Gateway和Citrix ADC 跨站脚本漏洞 — Citrix ADC and Citrix Gateway | 6.1 | Medium | 2023-07-10 |
| CVE-2015-10121 | WordPress plugin Beeliked Microsite 跨站脚本漏洞 — Beeliked Microsite Plugin | 3.5 | Low | 2023-07-10 |
| CVE-2015-10120 | WordPress plugin WDS Multisite Aggregate 跨站脚本漏洞 — WDS Multisite Aggregate Plugin | 3.5 | Low | 2023-07-10 |
| CVE-2015-10119 | WordPress plugin view-all-posts-pages 跨站脚本漏洞 — View All Posts Page Plugin | 3.5 | Low | 2023-07-10 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21615 条 CVE 漏洞。