CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 22584 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2021-32962 | AGG Software Web Serve 跨站脚本漏洞 — Web Server (webserver.dll) | 8.2 | High | 2022-05-24 |
| CVE-2022-1840 | Home Clean Services Management System 跨站脚本漏洞 — Home Clean Services Management System | 2.4 | Low | 2022-05-24 |
| CVE-2022-1819 | Student Information System 跨站脚本漏洞 — Student Information System | 2.4 | Low | 2022-05-24 |
| CVE-2022-0734 | Zyxel USG/ZyWALL 跨站脚本漏洞 — USG/ZyWALL series firmware | 5.8 | Medium | 2022-05-24 |
| CVE-2022-0900 | NetDataSoft DivvyDrive 跨站脚本漏洞 — DivvyDrive | 5.4 | Medium | 2022-05-23 |
| CVE-2022-1817 | Badminton Center Management System 跨站脚本漏洞 — Badminton Center Management System | 3.5 | Low | 2022-05-23 |
| CVE-2022-1816 | Zoo Management System 跨站脚本漏洞 — Zoo Management System | 3.5 | Low | 2022-05-23 |
| CVE-2022-1825 | Providence 跨站脚本漏洞 — collectiveaccess/providence | 6.1 | - | 2022-05-23 |
| CVE-2022-1558 | WordPress plugin Curtain 跨站脚本漏洞 — Curtain | 4.8 | - | 2022-05-23 |
| CVE-2022-1547 | WordPress plugin Check & Log Email 跨站脚本漏洞 — Check & Log Email | 6.1 | - | 2022-05-23 |
| CVE-2022-1320 | WordPress plugin Sliderby10Web 跨站脚本漏洞 — Sliderby10Web | 4.8 | - | 2022-05-23 |
| CVE-2022-1298 | WordPress plugin Tabs 跨站脚本漏洞 — Tabs | 4.8 | - | 2022-05-23 |
| CVE-2022-1268 | WordPress plugin Donate Extra 跨站脚本漏洞 — Donate Extra | 6.1 | - | 2022-05-23 |
| CVE-2022-1221 | WordPress plugin Imagemap Selector 跨站脚本漏洞 — Gwyn's Imagemap Selector | 6.1 | - | 2022-05-23 |
| CVE-2022-1218 | WordPress plugin Domain Replace 跨站脚本漏洞 — Domain Replace | 6.1 | - | 2022-05-23 |
| CVE-2022-1192 | WordPress plugin Turn off all comments 跨站脚本漏洞 — Turn off all comments | 6.1 | - | 2022-05-23 |
| CVE-2022-1093 | WordPress plugin WP Contacts Manager 跨站脚本漏洞 — WP Meta SEO | 4.8 | - | 2022-05-23 |
| CVE-2022-0346 | WordPress plugin XML Sitemap Generator 跨站脚本漏洞 — XML Sitemap Generator for Google | 6.1 | - | 2022-05-23 |
| CVE-2022-29432 | WordPress plugin wpDataTables跨站脚本漏洞 — wpDataTables – Tables & Table Charts (WordPress plugin) | 3.4 | Low | 2022-05-20 |
| CVE-2022-29428 | WordPress Plugin WP Slider 跨站脚本漏洞 — WP Slider Plugin | 4.1 | Medium | 2022-05-20 |
| CVE-2022-29426 | WordPress plugin Image Slider 跨站脚本漏洞 — Slideshow, Image Slider by 2J (WordPress plugin) | 5.4 | Medium | 2022-05-20 |
| CVE-2022-29425 | WordPress plugin Checkout Files Upload for WooCommerce跨站脚本漏洞 — Checkout Files Upload for WooCommerce (WordPress plugin) | 6.1 | Medium | 2022-05-20 |
| CVE-2022-29424 | WordPress plugin Image Hover Effects Ultimate跨站脚本漏洞 — Image Hover Effects Ultimate (WordPress plugin) | 4.8 | Medium | 2022-05-20 |
| CVE-2021-36833 | WordPress plugin MC4WP跨站脚本漏洞 — MC4WP: Mailchimp for WordPress | 4.8 | Medium | 2022-05-20 |
| CVE-2022-29183 | GoCD 跨站脚本漏洞 — gocd | 4.3 | Medium | 2022-05-20 |
| CVE-2022-29182 | GoCD 跨站脚本漏洞 — gocd | 4.3 | Medium | 2022-05-20 |
| CVE-2022-1806 | RTX 跨站脚本漏洞 — rtxteam/rtx | 6.1 | - | 2022-05-20 |
| CVE-2022-29449 | WordPress plugin Opal Hotel Room Booking 跨站脚本漏洞 — Opal Hotel Room Booking (WordPress plugin) | 4.1 | Medium | 2022-05-19 |
| CVE-2022-1730 | JGraph draw.io 跨站脚本漏洞 — jgraph/drawio | 5.4 | - | 2022-05-19 |
| CVE-2022-29230 | Hydrogen 跨站脚本漏洞 — hydrogen | 6.3 | Medium | 2022-05-18 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 22584 条 CVE 漏洞。