CWE-79 · 47.649 kayıt
Siteler arası betik çalıştırma
Neden olur?
Kullanıcı içeriği HTML olarak sayfaya ekleniyor. Tarayıcı içeriği veri olarak değil, kod olarak yorumlar.
Hatalı ve düzeltilmiş kod
Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.
Hatalı
commentEl.innerHTML = comment.body;Düzeltilmiş
commentEl.textContent = comment.body;Nasıl önlenir?
- 01Kullanıcı içeriğini metin olarak ekleyin ya da bağlama uygun kodlayın.
- 02HTML gerekiyorsa güvenilir bir temizleyiciden geçirin.
- 03İçerik güvenlik politikası başlığıyla ikinci bir savunma katmanı ekleyin.
Bu sınıftaki CVE’ler
10.000 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2019-3929Silahlaştırılmış | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1crestron · am-100 firmware · CWE-79 | Kritik9,8 | KEV | %99,0 | 30 Nis 2019 |
92Hemen | CVE-2024-42009Silahlaştırılmış | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails ofroundcube · webmail · CWE-79 | Kritik9,3 | KEV | %82,9 | 5 Ağu 2024 |
89Hemen | CVE-2023-34192Silahlaştırılmış | Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scrsynacor · zimbra collaboration suite · CWE-79 | Kritik9,0 | KEV | %77,3 | 6 Tem 2023 |
82Hemen | CVE-2019-18426Silahlaştırılmış | A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-swhatsapp · whatsapp · CWE-79 | Yüksek8,2 | KEV | %67,9 | 21 Oca 2020 |
80Hemen | CVE-2020-3580Silahlaştırılmış | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilitiescisco · secure firewall threat defense · CWE-79 | Orta6,1 | KEV | %85,6 | 21 Eki 2020 |
79Bu hafta | CVE-2020-11023Silahlaştırılmış | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Orta6,1 | KEV | %84,9 | 29 Nis 2020 |
77Bu hafta | CVE-2020-13965Silahlaştırılmış | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.roundcube · webmail · CWE-79 | Orta6,1 | KEV | %76,6 | 8 Haz 2020 |
76Bu hafta | CVE-2024-37383Silahlaştırılmış | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.roundcube · webmail · CWE-79 | Orta6,1 | KEV | %73,3 | 7 Haz 2024 |
76Bu hafta | CVE-2019-9978Silahlaştırılmış | The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameterwarfareplugins · social warfare · CWE-79 | Orta6,1 | KEV | %72,9 | 24 Mar 2019 |
76Bu hafta | CVE-2024-43573Silahlaştırılmış | Windows MSHTML Platform Spoofing Vulnerabilitymicrosoft · windows 10 1507 · CWE-79 | Yüksek8,1 | KEV | %46,1 | 8 Eki 2024 |
74Bu hafta | CVE-2023-5631Silahlaştırılmış | Stored XSS vulnerability in Roundcuberoundcube · webmail · CWE-79 | Orta5,4 | KEV | %75,9 | 18 Eki 2023 |
73Bu hafta | CVE-2023-43770Silahlaştırılmış | Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of roundcube · webmail · CWE-79 | Orta6,1 | KEV | %63,7 | 22 Eyl 2023 |
69Bu hafta | CVE-2023-37580Silahlaştırılmış | Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.synacor · zimbra collaboration suite · CWE-79 | Orta6,1 | KEV | %49,1 | 31 Tem 2023 |
68Bu hafta | CVE-2022-39197Silahlaştırılmış | An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTMhelpsystems · cobalt strike · CWE-79 | Orta6,1 | KEV | %46,4 | 21 Eyl 2022 |
66Bu hafta | CVE-2013-5223Silahlaştırılmış | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev.dlink · dsl-2760u firmware · CWE-79 | Orta5,4 | KEV | %50,8 | 19 Kas 2013 |
65Bu hafta | CVE-2021-26829Silahlaştırılmış | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.scadabr · scadabr · CWE-79 | Orta5,4 | KEV | %48,1 | 11 Haz 2021 |
64Bu hafta | CVE-2023-49785Kavram kanıtı | NextChat vulnerable to Server-Side Request Forgery and Cross-site Scriptingnextchat · nextchat · CWE-79 | Kritik9,8 | — | %83,2 | 11 Mar 2024 |
64Bu hafta | CVE-2022-28368Silahlaştırılmış | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (withdompdf project · dompdf · CWE-79 | Kritik9,8 | — | %82,4 | 2 Nis 2022 |
64Bu hafta | CVE-2020-35730Silahlaştırılmış | An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.roundcube · webmail · CWE-79 | Orta6,1 | KEV | %32,7 | 28 Ara 2020 |
63Bu hafta | CVE-2018-6882Silahlaştırılmış | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 synacor · zimbra collaboration suite · CWE-79 | Orta6,1 | KEV | %29,8 | 27 Mar 2018 |
63Bu hafta | CVE-2018-19953Silahlaştırılmış | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.qnap · qts · CWE-79 | Orta6,1 | KEV | %28,8 | 28 Eki 2020 |
62Bu hafta | CVE-2025-68461Silahlaştırılmış | Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG droundcube · webmail · CWE-79 | Orta6,1 | KEV | %26,8 | 18 Ara 2025 |
62Bu hafta | CVE-2024-44309Silahlaştırılmış | A cookie management issue was addressed with improved state management.debian · debian linux · CWE-79 | Orta6,3 | KEV | %22,6 | 19 Kas 2024 |
61Bu hafta | CVE-2024-27443Silahlaştırılmış | An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.zimbra · collaboration · CWE-79 | Orta6,1 | KEV | %23,6 | 12 Ağu 2024 |
61Bu hafta | CVE-2014-2120Silahlaştırılmış | Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackercisco · adaptive security appliance software · CWE-79 | Orta6,1 | KEV | %22,6 | 18 Mar 2014 |
- CVE-2019-392999Hemen
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99crestron · am-100 firmware30 Nis 2019
- CVE-2024-4200992Hemen
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %83roundcube · webmail5 Ağu 2024
- CVE-2023-3419289Hemen
Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scr
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %77synacor · zimbra collaboration suite6 Tem 2023
- CVE-2019-1842682Hemen
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-s
YüksekCVSS 8,2KEVSilahlaştırılmışEPSS %68whatsapp · whatsapp21 Oca 2020
- CVE-2020-358080Hemen
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %86cisco · secure firewall threat defense21 Eki 2020
- CVE-2020-1102379Bu hafta
Potential XSS vulnerability in jQuery
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %85jquery · jquery29 Nis 2020
- CVE-2020-1396577Bu hafta
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %77roundcube · webmail8 Haz 2020
- CVE-2024-3738376Bu hafta
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %73roundcube · webmail7 Haz 2024
- CVE-2019-997876Bu hafta
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %73warfareplugins · social warfare24 Mar 2019
- CVE-2024-4357376Bu hafta
Windows MSHTML Platform Spoofing Vulnerability
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %46microsoft · windows 10 15078 Eki 2024
- CVE-2023-563174Bu hafta
Stored XSS vulnerability in Roundcube
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %76roundcube · webmail18 Eki 2023
- CVE-2023-4377073Bu hafta
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %64roundcube · webmail22 Eyl 2023
- CVE-2023-3758069Bu hafta
Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %49synacor · zimbra collaboration suite31 Tem 2023
- CVE-2022-3919768Bu hafta
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTM
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %46helpsystems · cobalt strike21 Eyl 2022
- CVE-2013-522366Bu hafta
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev.
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %51dlink · dsl-2760u firmware19 Kas 2013
- CVE-2021-2682965Bu hafta
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %48scadabr · scadabr11 Haz 2021
- CVE-2023-4978564Bu hafta
NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting
KritikCVSS 9,8Kavram kanıtıEPSS %83nextchat · nextchat11 Mar 2024
- CVE-2022-2836864Bu hafta
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (with
KritikCVSS 9,8SilahlaştırılmışEPSS %82dompdf project · dompdf2 Nis 2022
- CVE-2020-3573064Bu hafta
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %33roundcube · webmail28 Ara 2020
- CVE-2018-688263Bu hafta
Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %30synacor · zimbra collaboration suite27 Mar 2018
- CVE-2018-1995363Bu hafta
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %29qnap · qts28 Eki 2020
- CVE-2025-6846162Bu hafta
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %27roundcube · webmail18 Ara 2025
- CVE-2024-4430962Bu hafta
A cookie management issue was addressed with improved state management.
OrtaCVSS 6,3KEVSilahlaştırılmışEPSS %23debian · debian linux19 Kas 2024
- CVE-2024-2744361Bu hafta
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %24zimbra · collaboration12 Ağu 2024
- CVE-2014-212061Bu hafta
Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attacker
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %23cisco · adaptive security appliance software18 Mar 2014