21658 vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)). AI Chinese analysis included.
CWE-79 represents a critical input validation weakness where software fails to properly sanitize user-supplied data before rendering it in web pages. Attackers typically exploit this vulnerability by injecting malicious scripts, often JavaScript, into trusted websites. When other users view the compromised page, the embedded code executes in their browsers, allowing the attacker to steal session cookies, hijack accounts, or redirect victims to phishing sites. This breach of trust undermines user privacy and application integrity. To prevent such attacks, developers must implement robust input validation and output encoding strategies. By strictly filtering incoming data and ensuring that all dynamic content is properly escaped before being processed by the browser, developers can neutralize dangerous inputs and effectively mitigate the risk of cross-site scripting vulnerabilities.
$username = $_GET['username']; echo '<div class="header"> Welcome, ' . $username . '</div>';http://trustedSite.example.com/welcome.php?username=<Script Language="Javascript">alert("You've been attacked!");</Script><% String eid = request.getParameter("eid"); %> ... Employee ID: <%= eid %><% protected System.Web.UI.WebControls.TextBox Login; protected System.Web.UI.WebControls.Label EmployeeID; ... EmployeeID.Text = Login.Text; %> <p><asp:label id="EmployeeID" runat="server" /></p>| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2018-3769 | ruby-grape ruby gem 跨站脚本漏洞 — ruby-grape ruby gem | 6.1 | - | 2018-07-05 |
| CVE-2018-8928 | Synology CardDAV Server Address Book Editor 跨站脚本漏洞 — CardDAV Server | 5.4 | - | 2018-07-05 |
| CVE-2018-11449 | Siemens SCALANCE M875 信任管理漏洞 — SCALANCE M875 | 7.8 | - | 2018-06-26 |
| CVE-2018-4842 | Siemens SCALANCE X-200 IRT和SCALANCE X-300 跨站脚本漏洞 — SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) | 4.8 | - | 2018-06-14 |
| CVE-2018-0149 | Cisco Integrated Management Controller Supervisor Software和UCS Director Software 跨站脚本漏洞 — Cisco Integrated Management Controller Supervisor and Cisco UCS Director unknown | 5.4 | - | 2018-06-07 |
| CVE-2018-0339 | Cisco Identity Services Engine 跨站脚本漏洞 — Cisco Identity Services Engine unknown | 6.1 | - | 2018-06-07 |
| CVE-2018-0340 | Cisco Unified Communications Manager 跨站脚本漏洞 — Cisco Unified Communications Manager unknown | 5.4 | - | 2018-06-07 |
| CVE-2018-0354 | Cisco Unity Connection 跨站脚本漏洞 — Cisco Unity Connection unknown | 6.1 | - | 2018-06-07 |
| CVE-2018-0356 | Cisco WebEx 跨站脚本漏洞 — Cisco WebEx unknown | 6.1 | - | 2018-06-07 |
| CVE-2018-0357 | Cisco WebEx 跨站脚本漏洞 — Cisco WebEx unknown | 6.1 | - | 2018-06-07 |
| CVE-2018-3716 | simplehttpserver 跨站脚本漏洞 — simplehttpserver node module | 5.4 | - | 2018-06-07 |
| CVE-2018-3717 | connect 跨站脚本漏洞 — connect node module | 5.4 | - | 2018-06-07 |
| CVE-2018-3726 | crud-file-server node module 跨站脚本漏洞 — crud-file-server node module | 5.4 | - | 2018-06-07 |
| CVE-2018-3735 | bracket-template 跨站脚本漏洞 — bracket-template node module | 6.1 | - | 2018-06-07 |
| CVE-2016-9490 | ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability — Applications Manager | 6.1 | - | 2018-06-05 |
| CVE-2018-8923 | Synology File Station Attachment Preview组件跨站脚本漏洞 — File Station | 5.4 | - | 2018-06-05 |
| CVE-2018-8924 | Synology Office Title Tootip 跨站脚本漏洞 — Office | 5.4 | - | 2018-06-05 |
| CVE-2017-0931 | html-janitor 跨站脚本漏洞 — html-janitor node module | 6.1 | - | 2018-06-04 |
| CVE-2017-16006 | Remarkable 跨站脚本漏洞 — remarkable node module | 6.1 | - | 2018-06-04 |
| CVE-2017-16008 | i18next 跨站脚本漏洞 — i18next node module | 6.1 | - | 2018-06-04 |
| CVE-2017-16009 | ag-grid 跨站脚本漏洞 — ag-grid node module | 6.1 | - | 2018-06-04 |
| CVE-2017-16016 | Sanitize-html 跨站脚本漏洞 — sanitize-html node module | 6.1 | - | 2018-06-04 |
| CVE-2017-16017 | Sanitize-html 跨站脚本漏洞 — sanitize-html node module | 6.1 | - | 2018-06-04 |
| CVE-2017-16018 | Restify 跨站脚本漏洞 — restify node module | 6.1 | - | 2018-06-04 |
| CVE-2017-16019 | GitBook online reader 跨站脚本漏洞 — gitbook node module | 5.4 | - | 2018-06-04 |
| CVE-2017-16022 | Morris.js 跨站脚本漏洞 — Morris.js node module | 5.4 | - | 2018-06-04 |
| CVE-2018-3755 | sexstatic 跨站脚本漏洞 — sexstatic | 6.1 | - | 2018-06-01 |
| CVE-2018-8921 | Synology Drive File Sharing Notify Toast 跨站脚本漏洞 — Drive | 5.4 | - | 2018-06-01 |
| CVE-2016-10531 | marked 跨站脚本漏洞 — marked node module | 6.1 | - | 2018-05-31 |
| CVE-2016-10537 | backbone.js 跨站脚本漏洞 — backbone node module | 5.4 | - | 2018-05-31 |
Vulnerabilities classified as CWE-79 (在Web页面生成时对输入的转义处理不恰当(跨站脚本)) represent 21658 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.