CWE-79 在Web页面生成时对输入的转义处理不恰当(跨站脚本) 类弱点 22442 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-79 即跨站脚本攻击,属于输入验证类漏洞。攻击者通过在网页中注入恶意脚本,利用服务器未正确过滤用户输入的特性,使受害者在浏览器中执行非预期代码,从而窃取会话令牌或篡改页面内容。开发者应避免此类风险,需严格对用户输入进行白名单验证,并在输出到 HTML 时实施上下文相关的编码与转义,确保危险字符被正确中和。
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2022-0936 | Autolab 跨站脚本漏洞 — autolab/autolab | 5.4 | - | 2022-04-11 |
| CVE-2022-1291 | tableExport.jquery.plugin 跨站脚本漏洞 — hhurz/tableexport.jquery.plugin | 6.1 | - | 2022-04-10 |
| CVE-2022-1290 | Trudesk 跨站脚本漏洞 — polonel/trudesk | 5.4 | - | 2022-04-10 |
| CVE-2022-1288 | School Club Application System跨站脚本漏洞 — School Club Application System | 4.3 | Medium | 2022-04-09 |
| CVE-2022-20741 | Cisco Secure Network Analytics 跨站脚本漏洞 — Cisco Secure Network Analytics | 5.4 | Medium | 2022-04-06 |
| CVE-2022-20781 | Cisco Web Security Appliance和Cisco AsyncOS 跨站脚本漏洞 — Cisco Web Security Appliance (WSA) | 5.4 | Medium | 2022-04-06 |
| CVE-2022-1234 | livehelperchat 跨站脚本漏洞 — livehelperchat/livehelperchat | 8.8 | - | 2022-04-06 |
| CVE-2022-24811 | Combodo iTop 跨站脚本漏洞 — iTop | 5.4 | Medium | 2022-04-05 |
| CVE-2022-28650 | JetBrains YouTrack 跨站脚本漏洞 — YouTrack | 7.3 | High | 2022-04-05 |
| CVE-2022-0602 | TastyIgniter 跨站脚本漏洞 — tastyigniter/tastyigniter | 5.4 | - | 2022-04-05 |
| CVE-2021-36826 | WordPress plugin weDevs WP Project Manager 跨站脚本漏洞 — WP Project Manager (WordPress plugin) | 5.4 | Medium | 2022-04-04 |
| CVE-2021-36851 | WordPress plugin Free Testimonials Slider Plugin 跨站脚本漏洞 — Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) | 4.1 | Medium | 2022-04-04 |
| CVE-2022-25618 | WordPress plugin wpDataTables 跨站脚本漏洞 — wpDataTables – Tables & Table Charts (WordPress plugin) | 3.4 | Low | 2022-04-04 |
| CVE-2022-25613 | WordPress plugin FV Flowplayer Video Player 跨站脚本漏洞 — FV Flowplayer Video Player (WordPress plugin) | 4.1 | Medium | 2022-04-04 |
| CVE-2022-24814 | Directus 跨站脚本漏洞 — directus | 8.8 | High | 2022-04-04 |
| CVE-2022-1170 | WordPress plugin Noo JobMonster WordPress theme 跨站脚本漏洞 — Noo JobMonster | 6.1 | - | 2022-04-04 |
| CVE-2022-1169 | Eyecix Careerfy跨站脚本漏洞 — Careerfy | 5.4 | - | 2022-04-04 |
| CVE-2022-1168 | WordPress plugin JobSearch WP JobSearch 跨站脚本漏洞 — WP JobSearch | 6.1 | - | 2022-04-04 |
| CVE-2022-1167 | WordPress plugin CareerUp Careerup WordPress theme 跨站脚本漏洞 — Careerup | 6.1 | - | 2022-04-04 |
| CVE-2022-1164 | WordPress plugin Wyzi Theme 跨站脚本漏洞 — WYZI Business Finder | 6.1 | - | 2022-04-04 |
| CVE-2022-0958 | WordPress plugin Mark Posts 跨站脚本漏洞 — Mark Posts | 4.8 | - | 2022-04-04 |
| CVE-2022-0901 | WordPress plugins Ad Inserter Free and Pro 跨站脚本漏洞 — Ad Inserter – Ad Manager & AdSense Ads | 6.1 | - | 2022-04-04 |
| CVE-2022-0884 | WordPress plugin Profile Builder 跨站脚本漏洞 — Profile Builder – User Profile & User Registration Forms | 4.8 | - | 2022-04-04 |
| CVE-2022-0864 | WordPress plugin UpdraftPlus WordPress Backup Plugin 跨站脚本漏洞 — UpdraftPlus WordPress Backup Plugin | 6.1 | - | 2022-04-04 |
| CVE-2022-0431 | WordPress plugin Insights from Google PageSpeed 跨站脚本漏洞 — Insights from Google PageSpeed | 6.1 | - | 2022-04-04 |
| CVE-2021-25113 | WordPress plugin Dropdown Menu Widget 跨站脚本漏洞 — Dropdown Menu Widget | 5.4 | - | 2022-04-04 |
| CVE-2021-25048 | WordPress plugin KingComposer 跨站脚本漏洞 — Page Builder: KingComposer – Free Drag and Drop page builder by King-Theme | 5.4 | - | 2022-04-04 |
| CVE-2021-23288 | Intelligent Power Protector 跨站脚本漏洞 — Intelligent Power Protector | 5.6 | Medium | 2022-04-01 |
| CVE-2021-23287 | Eaton Intelligent Power Manager 跨站脚本漏洞 — Intelligent Power Manager (IPM 1) | 5.6 | Medium | 2022-04-01 |
| CVE-2022-21830 | RocketChat LiveChat 跨站脚本漏洞 — Rocket.chat Livechat | 6.1 | - | 2022-04-01 |
CWE-79(在Web页面生成时对输入的转义处理不恰当(跨站脚本)) 是常见的弱点类别,本平台收录该类弱点关联的 22442 条 CVE 漏洞。