İçeriğe atla
Noroxi

CWE-79 · 47.649 kayıt

Siteler arası betik çalıştırma

Neden olur?

Kullanıcı içeriği HTML olarak sayfaya ekleniyor. Tarayıcı içeriği veri olarak değil, kod olarak yorumlar.

Hatalı ve düzeltilmiş kod

Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.

Hatalı

ts
commentEl.innerHTML = comment.body;

Düzeltilmiş

ts
commentEl.textContent = comment.body;

Nasıl önlenir?

  1. 01Kullanıcı içeriğini metin olarak ekleyin ya da bağlama uygun kodlayın.
  2. 02HTML gerekiyorsa güvenilir bir temizleyiciden geçirin.
  3. 03İçerik güvenlik politikası başlığıyla ikinci bir savunma katmanı ekleyin.

Bu sınıftaki CVE’ler

10.000 kayıt

  • The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    crestron · am-100 firmware30 Nis 2019

  • A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %83

    roundcube · webmail5 Ağu 2024

  • Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted scr

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %77

    synacor · zimbra collaboration suite6 Tem 2023

  • A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-s

    YüksekCVSS 8,2KEVSilahlaştırılmışEPSS %68

    whatsapp · whatsapp21 Oca 2020

  • Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Cross-Site Scripting Vulnerabilities

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %86

    cisco · secure firewall threat defense21 Eki 2020

  • CVE-2020-11023
    79Bu hafta

    Potential XSS vulnerability in jQuery

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %85

    jquery · jquery29 Nis 2020

  • CVE-2020-13965
    77Bu hafta

    An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %77

    roundcube · webmail8 Haz 2020

  • CVE-2024-37383
    76Bu hafta

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %73

    roundcube · webmail7 Haz 2024

  • CVE-2019-9978
    76Bu hafta

    The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %73

    warfareplugins · social warfare24 Mar 2019

  • CVE-2024-43573
    76Bu hafta

    Windows MSHTML Platform Spoofing Vulnerability

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %46

    microsoft · windows 10 15078 Eki 2024

  • CVE-2023-5631
    74Bu hafta

    Stored XSS vulnerability in Roundcube

    OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %76

    roundcube · webmail18 Eki 2023

  • CVE-2023-43770
    73Bu hafta

    Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %64

    roundcube · webmail22 Eyl 2023

  • CVE-2023-37580
    69Bu hafta

    Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %49

    synacor · zimbra collaboration suite31 Tem 2023

  • CVE-2022-39197
    68Bu hafta

    An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTM

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %46

    helpsystems · cobalt strike21 Eyl 2022

  • CVE-2013-5223
    66Bu hafta

    Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev.

    OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %51

    dlink · dsl-2760u firmware19 Kas 2013

  • CVE-2021-26829
    65Bu hafta

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

    OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %48

    scadabr · scadabr11 Haz 2021

  • CVE-2023-49785
    64Bu hafta

    NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting

    KritikCVSS 9,8Kavram kanıtıEPSS %83

    nextchat · nextchat11 Mar 2024

  • CVE-2022-28368
    64Bu hafta

    Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (with

    KritikCVSS 9,8SilahlaştırılmışEPSS %82

    dompdf project · dompdf2 Nis 2022

  • CVE-2020-35730
    64Bu hafta

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %33

    roundcube · webmail28 Ara 2020

  • CVE-2018-6882
    63Bu hafta

    Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %30

    synacor · zimbra collaboration suite27 Mar 2018

  • CVE-2018-19953
    63Bu hafta

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %29

    qnap · qts28 Eki 2020

  • CVE-2025-68461
    62Bu hafta

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG d

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %27

    roundcube · webmail18 Ara 2025

  • CVE-2024-44309
    62Bu hafta

    A cookie management issue was addressed with improved state management.

    OrtaCVSS 6,3KEVSilahlaştırılmışEPSS %23

    debian · debian linux19 Kas 2024

  • CVE-2024-27443
    61Bu hafta

    An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %24

    zimbra · collaboration12 Ağu 2024

  • CVE-2014-2120
    61Bu hafta

    Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attacker

    OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %23

    cisco · adaptive security appliance software18 Mar 2014

Tüm zafiyet sınıfları