CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 22442 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2022-1347 | Organizr 跨站脚本漏洞 — causefx/organizr | 6.9 | - | 2022-04-13 |
| CVE-2022-1346 | Organizr 跨站脚本漏洞 — causefx/organizr | 8.9 | - | 2022-04-13 |
| CVE-2022-1344 | Organizr 跨站脚本漏洞 — causefx/organizr | 5.4 | - | 2022-04-13 |
| CVE-2022-27505 | Citrix SD-WAN 跨站脚本漏洞 — Citrix SD-WAN | 6.1 | - | 2022-04-13 |
| CVE-2022-27503 | Citrix Systems Citrix StoreFront Server 跨站脚本漏洞 — StoreFront | 6.1 | - | 2022-04-13 |
| CVE-2022-1330 | fullpage.js 跨站脚本漏洞 — alvarotrigo/fullpage.js | 5.4 | - | 2022-04-12 |
| CVE-2022-28216 | SAP BusinessObjects Business Intelligence Platform 跨站脚本漏洞 — SAP BusinessObjects Business Intelligence Platform (BI Workspace) | 6.1 | - | 2022-04-12 |
| CVE-2022-28770 | SAPUI5 library 跨站脚本漏洞 — SAPUI5 (vbm library) | 6.1 | - | 2022-04-12 |
| CVE-2022-26105 | SAP NetWeaver Enterprise Portal 跨站脚本漏洞 — SAP NetWeaver Enterprise Portal | 6.1 | - | 2022-04-12 |
| CVE-2022-24833 | PrivateBin 跨站脚本漏洞 — PrivateBin | 8.2 | High | 2022-04-11 |
| CVE-2022-27845 | WordPress plugin PlausibleHQ Plausible Analytics跨站脚本漏洞 — Plausible Analytics (WordPress plugin) | 4.8 | Medium | 2022-04-11 |
| CVE-2022-22571 | Incapptic Connect 跨站脚本漏洞 — Ivanti Incapptic Connect | 4.8 | - | 2022-04-11 |
| CVE-2021-36893 | WordPress plugin Responsive Tabs 跨站脚本漏洞 — Responsive Tabs (WordPress plugin) | 4.8 | Medium | 2022-04-11 |
| CVE-2021-36846 | WordPress plugin Premio Chaty跨站脚本漏洞 — Chaty (WordPress plugin) | 4.8 | Medium | 2022-04-11 |
| CVE-2021-36896 | WordPress plugin Pricing Table 跨站脚本漏洞 — Pricing Table (WordPress plugin) | 4.8 | Medium | 2022-04-11 |
| CVE-2021-36848 | WordPress plugin Social Media Feather跨站脚本漏洞 — Social Media Feather (WordPress plugin) | 3.4 | Low | 2022-04-11 |
| CVE-2021-36910 | WordPress plugin WP-Appbox 跨站脚本漏洞 — WP-Appbox (WordPress plugin) | 3.4 | Low | 2022-04-11 |
| CVE-2022-1007 | WordPress plugin advanced-booking-calendar 跨站脚本漏洞 — Advanced Booking Calendar | 6.1 | - | 2022-04-11 |
| CVE-2022-0969 | WordPress plugin Optimole 跨站脚本漏洞 — Image optimization & Lazy Load by Optimole | 4.8 | - | 2022-04-11 |
| CVE-2022-0892 | WordPress Export All URLs plugin跨站脚本漏洞 — Export All URLs | 6.1 | - | 2022-04-11 |
| CVE-2022-0840 | WordPress Easy Social Icons plugin跨站脚本漏洞 — Easy Social Icons | 4.8 | - | 2022-04-11 |
| CVE-2022-0728 | WordPress plugin Easy Smooth Scroll Links跨站脚本漏洞 — Easy Smooth Scroll Links | 4.8 | - | 2022-04-11 |
| CVE-2022-0531 | WordPress和WordPress plugin 跨站脚本漏洞 — Migration, Backup, Staging – WPvivid | 6.1 | - | 2022-04-11 |
| CVE-2022-0471 | WordPress Favicon by RealFaviconGenerator plugin 跨站脚本漏洞 — Favicon by RealFaviconGenerator | 6.1 | - | 2022-04-11 |
| CVE-2022-0447 | WordPress plugin Post Grid 跨站脚本漏洞 — Post Grid | 5.4 | - | 2022-04-11 |
| CVE-2022-0314 | WordPress plugin Nimble Page Builder跨站脚本漏洞 — Nimble Page Builder | 6.1 | - | 2022-04-11 |
| CVE-2022-0271 | WordPress plugin LearnPress 跨站脚本漏洞 — LearnPress – WordPress LMS Plugin | 6.1 | - | 2022-04-11 |
| CVE-2021-25090 | WordPress plugin 跨站脚本漏洞 — Portfolio Gallery, Product Catalog – Grid KIT Portfolio | 4.1 | - | 2022-04-11 |
| CVE-2021-24987 | WordPress plugin 跨站脚本漏洞 — Social Share, Social Login and Social Comments Plugin – Super Socializer | 6.1 | - | 2022-04-11 |
| CVE-2021-24986 | Wordpress plugin Post Grid 跨站脚本漏洞 — Post Grid | 6.1 | - | 2022-04-11 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 22442 条 CVE 漏洞。