CWE-79 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-79 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2019-3929The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P f…99.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2020-3580Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) So…85.6%보통6.1● 실제 악용이 확인됨CVE-2020-11023In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option>…84.9%보통6.1● 실제 악용이 확인됨CVE-2024-42009A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a rem…82.9%심각9.3● 실제 악용이 확인됨CVE-2023-34192Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to …77.3%심각9.0● 실제 악용이 확인됨CVE-2020-13965An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via …76.6%보통6.1● 실제 악용이 확인됨CVE-2023-5631Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-…75.9%보통5.4● 실제 악용이 확인됨CVE-2024-37383Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.73.3%보통6.1
전체 목록
120건
CVE-2019-9978악용 확인The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=…72.9%보통6.1
CVE-2019-18426악용 확인A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions p…67.9%높음8.2
CVE-2023-43770악용 확인Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages …63.7%보통6.1
CVE-2013-5223악용 확인Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authent…50.8%보통5.4
CVE-2023-37580악용 확인Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.49.1%보통6.1
CVE-2021-26829악용 확인OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.sht…48.0%보통5.4
CVE-2022-39197악용 확인An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a …46.4%보통6.1
CVE-2020-35730악용 확인An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. …32.9%보통6.1
CVE-2018-6882랜섬웨어 악용Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collabo…29.8%보통6.1
CVE-2018-19953랜섬웨어 악용If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. Q…28.8%보통6.1
CVE-2025-68461악용 확인Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability v…26.8%보통6.1
CVE-2024-27443악용 확인An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability…23.6%보통6.1
CVE-2024-44309악용 확인A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, …22.6%보통6.3
CVE-2014-2120악용 확인Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) S…22.6%보통6.1
CVE-2018-19943랜섬웨어 악용If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. Q…21.5%보통5.4
CVE-2025-66376악용 확인Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascadin…20.2%보통6.1
CVE-2022-27926악용 확인A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Co…17.6%보통6.1
CVE-2024-11182악용 확인An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mai…17.6%보통5.3
CVE-2021-1879악용 확인This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14…7.1%보통6.1
CVE-2012-0767악용 확인Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 …6.2%보통6.1
CVE-2025-27915악용 확인An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XS…4.0%보통5.4
CVE-2025-48700악용 확인An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting…1.7%보통6.1
CVE-2026-42897악용 확인Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Ser…0.5%보통6.1
CVE-2026-75744Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could…1.2%높음8.1
CVE-2026-54645CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the des…1.1%보통4.8
CVE-2026-54644CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php …0.9%보통6.1
CVE-2026-93922SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allo…0.8%높음8.6
CVE-2026-76002ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to conv…0.7%보통6.1
CVE-2026-88060Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript…0.7%높음8.6
CVE-2026-69356Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Ser…0.7%심각9.3
CVE-2026-63523Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business all…0.7%보통6.5
CVE-2026-84108IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neut…0.6%높음8.1
CVE-2026-84031IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to…0.6%심각9.0
CVE-2026-82832IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to…0.6%심각9.6
CVE-2026-49995Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter…0.6%보통4.8
CVE-2026-93923SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, a…0.6%높음8.6
CVE-2026-73546Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.…0.6%높음7.4
CVE-2026-91921Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering eng…0.6%보통5.1
CVE-2026-45381Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search en…0.6%보통5.1
CVE-2026-77615Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as …0.6%높음8.7
CVE-2026-4637Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XS…0.6%보통5.1
CVE-2026-92144The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to …0.5%높음7.2
CVE-2026-83946Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an…0.6%높음8.2
CVE-2026-95665MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmatio…0.5%보통5.1
CVE-2026-88804An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-si…0.5%심각9.6
CVE-2026-92985SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them i…0.5%높음8.6
CVE-2026-100641SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card…0.5%높음8.6
CVE-2026-73169Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-…0.5%보통6.3
CVE-2026-89412The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to St…0.5%높음7.2
CVE-2026-84074IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to…0.5%높음8.9
CVE-2026-84106IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to…0.5%높음8.9
CVE-2026-84070IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to…0.5%높음8.9
CVE-2026-88058Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript…0.5%높음8.6
CVE-2026-83561The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scriptin…0.5%높음7.2
CVE-2026-79294Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to ex…0.5%보통6.1
CVE-2026-88824The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowin…0.5%높음8.8
CVE-2026-85122The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against…0.5%높음8.8
CVE-2026-85680The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile …0.5%높음8.8
CVE-2026-88825The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance setting…0.5%높음8.8
CVE-2026-54355MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers …0.5%보통5.3
CVE-2026-88869AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerab…0.5%심각9.3
CVE-2026-55105Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prio…0.5%높음7.7
CVE-2026-87915The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for …0.5%높음7.2
CVE-2026-45143Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS store…0.5%심각9.0
CVE-2026-67237RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a be…0.5%높음7.5
CVE-2026-84829The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to …0.5%높음8.8
CVE-2026-44203Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Co…0.5%높음8.3
CVE-2026-53555SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authent…0.5%보통5.1
CVE-2026-100639SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/pr…0.5%높음8.6
CVE-2026-76200Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an att…0.5%심각9.3
CVE-2026-76201Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an att…0.5%심각9.3
CVE-2026-95396A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected…0.5%낮음2.1
CVE-2026-44793Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoint…0.4%높음7.0
CVE-2026-94035A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown functi…0.5%낮음2.1
CVE-2026-93659Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in chec…0.5%심각9.3
CVE-2026-90795A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown …0.4%낮음2.1
CVE-2026-69417Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share…0.4%보통5.4
CVE-2026-86294A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is …0.4%낮음2.1
CVE-2026-58491Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/ss…0.5%심각9.3
CVE-2026-77912A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an a…0.4%높음7.4
CVE-2026-85127The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files u…0.4%높음8.8
CVE-2026-85385Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without…0.4%높음7.7
CVE-2026-86238A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unkn…0.4%낮음2.1
CVE-2026-95661MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selec…0.4%보통5.1
CVE-2026-92986SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characte…0.4%높음8.6
CVE-2026-88788The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values befor…0.4%보통6.8
CVE-2026-88993The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before out…0.4%보통6.8
CVE-2026-84902The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization c…0.4%보통6.8
CVE-2026-84223The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site…0.4%보통6.8
CVE-2026-92991The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API…0.4%보통5.4
CVE-2026-93778The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Te…0.4%높음7.2
CVE-2026-88057Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript…0.4%보통5.3
CVE-2026-69402Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share…0.4%보통5.4
CVE-2026-100313A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3f…0.4%낮음2.1
CVE-2026-84397Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused…0.4%보통5.4
CVE-2026-100643SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, …0.4%높음8.5
CVE-2026-85653The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attr…0.4%보통6.4
CVE-2026-69690Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Share…0.4%보통5.4
CVE-2026-5400The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filt…0.4%보통6.4
CVE-2026-95682MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MIS…0.4%보통4.8
CVE-2026-86784The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configura…0.4%보통6.8
CVE-2026-84088The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a wid…0.4%보통6.8
CVE-2026-76558The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the…0.4%보통6.8
CVE-2026-92140Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook pa…0.4%보통6.8
CVE-2026-93432A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template…0.4%보통6.1
CVE-2026-95657A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function se…0.4%낮음2.0
CVE-2026-15639An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run…0.4%심각9.3
CVE-2026-87793The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-…0.4%보통5.1
CVE-2026-93956A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::…0.4%낮음2.0
CVE-2026-94045A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of …0.4%낮음2.0
CVE-2026-78252GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.…0.4%높음8.2
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.