21658 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.
CWE-79 represents a critical input validation weakness where software fails to properly sanitize user-supplied data before rendering it in web pages. Attackers typically exploit this vulnerability by injecting malicious scripts, often JavaScript, into trusted websites. When other users view the compromised page, the embedded code executes in their browsers, allowing the attacker to steal session cookies, hijack accounts, or redirect victims to phishing sites. This breach of trust undermines user privacy and application integrity. To prevent such attacks, developers must implement robust input validation and output encoding strategies. By strictly filtering incoming data and ensuring that all dynamic content is properly escaped before being processed by the browser, developers can neutralize dangerous inputs and effectively mitigate the risk of cross-site scripting vulnerabilities.
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2020-15162 | Stored XSS in PrestaShop — PrestaShop | 5.4 | Medium | 2020-09-24 |
| CVE-2020-15161 | Potential XSS in PrestaShop — PrestaShop | 5.4 | Medium | 2020-09-24 |
| CVE-2020-8348 | Lenovo Enterprise Network Disk 跨站脚本漏洞 — Enterprise Network Disk | 6.1 | Medium | 2020-09-24 |
| CVE-2020-8347 | Lenovo Enterprise Network Disk 跨站脚本漏洞 — Enterprise Network Disk | 6.1 | Medium | 2020-09-24 |
| CVE-2019-15969 | Cisco Web Security Appliance Management Interface Cross-Site Scripting Vulnerability — Cisco Web Security Appliance (WSA) | 6.1 | - | 2020-09-23 |
| CVE-2019-16025 | Cisco Emergency Responder Stored Cross-Site Scripting Vulnerability — Cisco Emergency Responder | 5.4 | - | 2020-09-23 |
| CVE-2020-3137 | Cisco Email Security Appliance Cross-Site Scripting Vulnerability — Cisco Email Security Appliance (ESA) | 6.1 | - | 2020-09-23 |
| CVE-2020-8245 | Citrix Systems 多款产品跨站脚本漏洞 — Citrix ADC, Citrix Gateway | 8.8 | - | 2020-09-18 |
| CVE-2020-15183 | Reflected XSS leading to RCE in SoyCMS — soycms | 8.4 | High | 2020-09-17 |
| CVE-2020-10748 | Red Hat Keycloak 跨站脚本漏洞 — keycloak | 6.1 | - | 2020-09-16 |
| CVE-2020-15179 | HTML Injection in ScratchSig — wiki-scratchsig | 8.0 | High | 2020-09-15 |
| CVE-2020-15178 | Potential XSS in PrestaShop contactform — contactform | 8.0 | High | 2020-09-15 |
| CVE-2020-8340 | IBM BladeCenter 跨站脚本漏洞 — System x IMM2 firmware for: x240, Machine Types: 7162, 2588; x440, Machine Type 7167, 2590 ; x3750 M4, Machine Type: 8753 ; x3250 M6, Machine type 3633, 3943 ; nx360 M5, Machine type 5465, 5467 ; x280/x480/x880 X6 , Machine Type 7196, 4258 ; x3850 X6 and x3950 X6, Machine type 6241 ; x3550 M5, Machine Type 5463, 8869 ; x3650 M5, Machine Type 5462, 8871; x3500 M5, Machine Type 5464, 5478 | 6.3 | Medium | 2020-09-15 |
| CVE-2020-15169 | XSS in Action View — actionview | 5.4 | Medium | 2020-09-11 |
| CVE-2020-16218 | Philips Patient Monitoring Devices Cross-site Scripting — Patient Information Center iX (PICiX) | 4.3 | - | 2020-09-11 |
| CVE-2020-9734 | Stored XSS in AEM Forms component — Experience Manager | 9.0 | Critical | 2020-09-10 |
| CVE-2020-9742 | Reflected XSS in AEM Inbox module — Experience Manager | 9.0 | Critical | 2020-09-10 |
| CVE-2020-9741 | Stored XSS in AEM Forms Components — Experience Manager | 9.0 | Critical | 2020-09-10 |
| CVE-2020-9736 | Stored XSS in AEM's Content Repository Development Environment — Experience Manager | 6.8 | Medium | 2020-09-10 |
| CVE-2020-9735 | Stored XSS in AEM's Content Repository Development Environment — Experience Manager | 6.8 | Medium | 2020-09-10 |
| CVE-2020-9732 | Stored XSS in AEM Sites Components — Experience Manager | 9.0 | Critical | 2020-09-10 |
| CVE-2020-9738 | Stored XSS in AEM's Content Repository Development Environment — Experience Manager | 6.8 | Medium | 2020-09-10 |
| CVE-2020-9737 | Stored XSS in AEM's Content Repository Development Environment — Experience Manager | 6.8 | Medium | 2020-09-10 |
| CVE-2020-9740 | Stored XSS in AEM Design Importer Component — Experience Manager | 9.0 | Critical | 2020-09-10 |
| CVE-2020-2036 | PAN-OS: Reflected Cross-Site Scripting (XSS) vulnerability in management web interface — PAN-OS | 8.8 | High | 2020-09-09 |
| CVE-2019-11928 | WhatsApp 跨站脚本漏洞 — WhatsApp Desktop | 6.1 | - | 2020-09-03 |
| CVE-2020-16210 | Red Lion N-Tron 跨站脚本漏洞 — N-Tron 702-W / 702M12-W | 9.6 | - | 2020-09-01 |
| CVE-2020-16206 | Red Lion N-Tron 跨站脚本漏洞 — N-Tron 702-W / 702M12-W | 8.9 | - | 2020-09-01 |
| CVE-2020-15159 | Cross Site Scripting leading to RCE in baserCMS — basercms | 7.6 | High | 2020-08-28 |
| CVE-2020-15155 | Cross-Site Scripting in baserCMS — basercms | 7.3 | High | 2020-08-28 |
Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21658 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.