CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 22442 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-32208 | Microsoft Edge 欺骗漏洞 — Microsoft Edge (Chromium-based) | 8.8 | High | 2026-06-19 |
| CVE-2026-12621 | GridTime™ 3000 GNSS 时间服务器密码重置重定向跨站脚本漏洞 — GridTime 3000 | - | - | 2026-06-19 |
| CVE-2026-12619 | GridTime 3000 CSRF转XSS漏洞 — GridTime 3000 | - | - | 2026-06-19 |
| CVE-2026-12430 | Blocksy Companion 2.1.45 编辑者权限存储型XSS漏洞 — Blocksy Companion | 4.4 | Medium | 2026-06-19 |
| CVE-2026-12157 | BetterDocs 4.5.3 存储型XSS漏洞 — BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot | 6.4 | Medium | 2026-06-19 |
| CVE-2026-1856 | Appointment Booking Calendar 1.4.4 存储型跨站脚本漏洞 — Creavi Appointment Booking Calendar | 6.4 | Medium | 2026-06-19 |
| CVE-2026-12048 | pgAdmin 4 存储型XSS漏洞 — pgAdmin 4 | 9.3 | Critical | 2026-06-18 |
| CVE-2026-12047 | pgAdmin 4 云端认证/部署端点HTML注入漏洞 — pgAdmin 4 | 3.5 | Low | 2026-06-18 |
| CVE-2026-22674 | Hashgraph Guardian 存储型跨站脚本漏洞 — guardian | 4.8 | Medium | 2026-06-18 |
| CVE-2026-43915 | Coturn web-admin界面存储型XSS漏洞 — coturn | 5.4 | Medium | 2026-06-18 |
| CVE-2026-11982 | Admin2 Pages API 存储型跨站脚本漏洞 — grav-plugin-api | - | - | 2026-06-18 |
| CVE-2026-54221 | UBB.threads 反射型 XSS 漏洞 — UBB.threads | - | - | 2026-06-18 |
| CVE-2026-54219 | UBB.threads 存储型XSS漏洞 — UBB.threads | - | - | 2026-06-18 |
| CVE-2026-40457 | LMS 反射型 XSS 漏洞 — LMS | - | - | 2026-06-18 |
| CVE-2026-56009 | WordPress Bricksable插件 <= 1.6.83 跨站脚本漏洞 — Bricksable for Bricks Builder | 5.9 | Medium | 2026-06-18 |
| CVE-2026-56007 | WordPress Ocean Product Sharing <= 2.2.2 跨站脚本漏洞 — Ocean Product Sharing | 5.9 | Medium | 2026-06-18 |
| CVE-2026-2021 | Slideshow Gallery LITE <=1.8.5 已授权存储型XSS漏洞 — Slideshow Gallery LITE | 6.4 | Medium | 2026-06-18 |
| CVE-2026-8039 | Fancy Testimonials <= 1.0 存储型跨站脚本漏洞 — Fancy Testimonials | 6.4 | Medium | 2026-06-18 |
| CVE-2026-12137 | WooCommerce Customize My Account <= 4.3.6 反射型XSS漏洞 — SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager | 6.1 | Medium | 2026-06-18 |
| CVE-2026-12098 | PowerPress Podcasting插件 11.16.8 及以下版本存储型XSS漏洞 — PowerPress Podcasting plugin by Blubrry | 6.4 | Medium | 2026-06-18 |
| CVE-2026-12136 | WooCommerce Customize My Account <=4.3.6 存储型XSS漏洞 — SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager | 6.4 | Medium | 2026-06-18 |
| CVE-2026-55746 | Cotonti 通过PFS文件夹标题的存储型XSS漏洞 — Cotonti | 7.6 | High | 2026-06-18 |
| CVE-2026-11358 | Orbit Fox <= 3.0.6 管理员存储型XSS漏洞 — Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More | 4.4 | Medium | 2026-06-18 |
| CVE-2026-11402 | Services Section Block 1.4.4 存储型XSS漏洞 — Services Section Block – Showcase Service Details in Grid or Columns | 6.4 | Medium | 2026-06-18 |
| CVE-2026-44644 | harttle liquidjs 跨站脚本漏洞 — liquidjs | 6.1 | Medium | 2026-06-17 |
| CVE-2026-54386 | marimo 跨站脚本漏洞 — marimo | 6.1 | Medium | 2026-06-17 |
| CVE-2026-48821 | Shaarli Community shaarli 跨站脚本漏洞 — Shaarli | 5.8 | Medium | 2026-06-17 |
| CVE-2026-48823 | Shaarli Community shaarli 跨站脚本漏洞 — Shaarli | 4.8 | Medium | 2026-06-17 |
| CVE-2026-48822 | Shaarli Community shaarli 跨站脚本漏洞 — Shaarli | 5.8 | Medium | 2026-06-17 |
| CVE-2026-10850 | plane 跨站脚本漏洞 — Plane | - | - | 2026-06-17 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 22442 条 CVE 漏洞。