CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 22442 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-68166 | JetBrains TeamCity 跨站脚本漏洞 — TeamCity | 5.4 | Medium | 2025-12-16 |
| CVE-2025-68165 | JetBrains TeamCity 跨站脚本漏洞 — TeamCity | 5.4 | Medium | 2025-12-16 |
| CVE-2025-68163 | JetBrains TeamCity 跨站脚本漏洞 — TeamCity | 3.5 | Low | 2025-12-16 |
| CVE-2025-11220 | WordPress plugin Elementor 跨站脚本漏洞 — Elementor Website Builder – more than just a page builder | 6.4 | Medium | 2025-12-16 |
| CVE-2025-68078 | WordPress plugin Salient Portfolio 跨站脚本漏洞 — Salient Portfolio | 6.5 | Medium | 2025-12-16 |
| CVE-2025-68080 | WordPress plugin User Avatar - Reloaded 安全漏洞 — User Avatar - Reloaded | 6.5 | Medium | 2025-12-16 |
| CVE-2025-68079 | WordPress plugin Salient Shortcodes 跨站脚本漏洞 — Salient Shortcodes | 6.5 | Medium | 2025-12-16 |
| CVE-2025-68076 | WordPress plugin Stockholm Core 安全漏洞 — Stockholm Core | 6.5 | Medium | 2025-12-16 |
| CVE-2025-68070 | WordPress plugin VK Google Job Posting Manager 跨站脚本漏洞 — VK Google Job Posting Manager | 6.5 | Medium | 2025-12-16 |
| CVE-2025-68077 | WordPress plugin Stockholm 安全漏洞 — Stockholm | 6.5 | Medium | 2025-12-16 |
| CVE-2025-67983 | WordPress plugin WP Visitor Statistics 跨站脚本漏洞 — WP Visitor Statistics (Real Time Traffic) | 6.5 | Medium | 2025-12-16 |
| CVE-2025-67986 | WordPress plugin Document Library Lite 安全漏洞 — Document Library Lite | 5.9 | Medium | 2025-12-16 |
| CVE-2025-67951 | WordPress plugin WPZOOM Addons for Elementor 安全漏洞 — WPZOOM Addons for Elementor | 6.5 | Medium | 2025-12-16 |
| CVE-2025-67912 | WordPress plugin Stars Testimonials 安全漏洞 — Stars Testimonials | 6.5 | Medium | 2025-12-16 |
| CVE-2025-68115 | Parse Server 跨站脚本漏洞 — parse-server | 6.1AI | MediumAI | 2025-12-16 |
| CVE-2025-64338 | ClipBucket V5 安全漏洞 — clipbucket-v5 | - | - | 2025-12-15 |
| CVE-2025-14722 | DMadmin 代码注入漏洞 — DMadmin | 2.4 | Low | 2025-12-15 |
| CVE-2023-53891 | Blackcat CMS 安全漏洞 — Blackcat CMS | 5.4AI | MediumAI | 2025-12-15 |
| CVE-2023-53890 | Perch CMS 安全漏洞 — Perch | 5.4AI | MediumAI | 2025-12-15 |
| CVE-2023-53887 | Zomplog 安全漏洞 — Zomplog | 5.4AI | MediumAI | 2025-12-15 |
| CVE-2023-53884 | Webedition CMS 安全漏洞 — Webedition CMS | 5.4AI | MediumAI | 2025-12-15 |
| CVE-2023-53882 | JLex GuestBook 跨站脚本漏洞 — JLex GuestBook | 6.1AI | MediumAI | 2025-12-15 |
| CVE-2023-53880 | Lucee 跨站脚本漏洞 — Lucee | 5.4AI | MediumAI | 2025-12-15 |
| CVE-2023-53870 | Jorani 跨站脚本漏洞 — Jorani | 6.1AI | MediumAI | 2025-12-15 |
| CVE-2025-14387 | WordPress plugin LearnPress – WordPress LMS Plugin 跨站脚本漏洞 — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | 6.4 | Medium | 2025-12-15 |
| CVE-2025-13728 | WordPress plugin FluentAuth – The Ultimate Authorization & Security Plugin for WordPress 跨站脚本漏洞 — FluentAuth – The Ultimate Authorization & Security Plugin for WordPress | 6.4 | Medium | 2025-12-15 |
| CVE-2025-13610 | WordPress plugin RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login 跨站脚本漏洞 — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | 6.4 | Medium | 2025-12-15 |
| CVE-2025-13367 | WordPress plugin User Registration & Membership 跨站脚本漏洞 — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | 6.4 | Medium | 2025-12-15 |
| CVE-2025-13608 | WordPress plugin CC Child Pages 跨站脚本漏洞 — CC Child Pages | 6.4 | Medium | 2025-12-15 |
| CVE-2025-37732 | Elastic Kibana 安全漏洞 — Kibana | 5.4 | Medium | 2025-12-15 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 22442 条 CVE 漏洞。