CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 21660 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-37272 | Cockpit 跨站脚本漏洞 — joc-cockpit | 6.3 | Medium | 2023-07-13 |
| CVE-2023-36473 | Discourse 跨站脚本漏洞 — discourse | 6.8 | Medium | 2023-07-13 |
| CVE-2023-30564 | BD Alaris System with Guardrails Suite MX 跨站脚本漏洞 — BD Alarisâ„¢ Systems Manager | 6.9 | Medium | 2023-07-13 |
| CVE-2023-30563 | BD Alaris System with Guardrails Suite MX 跨站脚本漏洞 — BD Alarisâ„¢ Systems Manager | 8.2 | High | 2023-07-13 |
| CVE-2023-3660 | Campcodes Retro Cellphone Online Store 跨站脚本漏洞 — Retro Cellphone Online Store | 2.4 | Low | 2023-07-13 |
| CVE-2023-3659 | AC Repair and Services System 跨站脚本漏洞 — AC Repair and Services System | 3.5 | Low | 2023-07-13 |
| CVE-2023-3319 | iDisplay PlatPlay DS 跨站脚本漏洞 — PlatPlay DS | 5.4 | Medium | 2023-07-13 |
| CVE-2023-3642 | GZ Scripts Vacation Rental Website 跨站脚本漏洞 — Vacation Rental Website | 4.3 | Medium | 2023-07-12 |
| CVE-2023-3641 | NodCMS 跨站脚本漏洞 — NodCMS | 4.3 | Medium | 2023-07-12 |
| CVE-2023-38066 | JetBrains TeamCity 跨站脚本漏洞 — TeamCity | 4.6 | Medium | 2023-07-12 |
| CVE-2023-38065 | JetBrains TeamCity 跨站脚本漏洞 — TeamCity | 4.6 | Medium | 2023-07-12 |
| CVE-2023-38063 | JetBrains TeamCity 跨站脚本漏洞 — TeamCity | 4.6 | Medium | 2023-07-12 |
| CVE-2023-38061 | JetBrains TeamCity 跨站脚本漏洞 — TeamCity | 4.6 | Medium | 2023-07-12 |
| CVE-2023-3087 | WordPress Plugin FluentSMTP 跨站脚本漏洞 — FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider | 7.2 | High | 2023-07-12 |
| CVE-2023-3081 | WordPress Plugin WP Mail Logging 跨站脚本漏洞 — WP Mail Logging | 7.2 | High | 2023-07-12 |
| CVE-2023-3167 | WordPress Plugin Mail Queue 跨站脚本漏洞 — Mail Queue | 7.2 | High | 2023-07-12 |
| CVE-2023-3166 | WordPress Plugin Lana Email Logger 跨站脚本漏洞 — Lana Email Logger | 7.2 | High | 2023-07-12 |
| CVE-2023-3369 | WordPress Plugin About Me 3000 widget 跨站脚本漏洞 — About Me 3000 widget | 4.4 | Medium | 2023-07-12 |
| CVE-2023-3092 | WordPress Plugin SMTP Mail 跨站脚本漏洞 — SMTP Mail | 7.2 | High | 2023-07-12 |
| CVE-2023-3088 | WordPress Plugin WP Mail Log 跨站脚本漏洞 — WP Mail Log | 7.2 | High | 2023-07-12 |
| CVE-2023-3158 | WordPress Plugin Mail Control 跨站脚本漏洞 — Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking | 7.2 | High | 2023-07-12 |
| CVE-2023-3082 | WordPress Plugin Post SMTP 跨站脚本漏洞 — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | 7.2 | High | 2023-07-12 |
| CVE-2023-3168 | WordPress Plugin WP Reroute Email 跨站脚本漏洞 — WP Reroute Email | 7.2 | High | 2023-07-12 |
| CVE-2023-3093 | WordPress Plugin YaySMTP 跨站脚本漏洞 — YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service | 7.2 | High | 2023-07-12 |
| CVE-2023-3135 | WordPress Plugin Mailtree Log Mail 跨站脚本漏洞 — Mailtree Log Mail | 7.2 | High | 2023-07-12 |
| CVE-2023-3080 | WordPress Plugin WP Mail Catcher 跨站脚本漏洞 — Mail logging – WP Mail Catcher | 7.2 | High | 2023-07-12 |
| CVE-2023-3122 | WordPress Plugin GD Mail Queue 跨站脚本漏洞 — GD Mail Queue | 7.2 | High | 2023-07-12 |
| CVE-2023-23756 | Joomla 跨站脚本漏洞 — oneVote component for Joomla | 6.1 | - | 2023-07-11 |
| CVE-2023-37280 | Pimcore 跨站脚本漏洞 — admin-ui-classic-bundle | 5.0 | Medium | 2023-07-11 |
| CVE-2023-34089 | Decidim 跨站脚本漏洞 — decidim | 8.1 | High | 2023-07-11 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 21660 条 CVE 漏洞。