Weaknesses of type CWE-79

28,639 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2019-1701MEDIUMCisco Adaptive Security Appliance and Firepower Threat Defense Software WebVPN Cross-Site Scripting VulnerabilitiesEPSS 0.9%CVE-2020-5334HIGHRSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unEPSS 0.9%CVE-2024-12833HIGHPaessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass VulnerabilityEPSS 0.9%CVE-2018-15426—Cisco Unity Connection Stored Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2023-25835HIGHBUG-000153659 ArcGIS Enterprise Sites has a stored XSS vulnerabilityEPSS 0.9%CVE-2025-52561MEDIUMHTMLSanitizer.jl Possible XSSEPSS 0.9%CVE-2024-33298MEDIUMMicroweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new baEPSS 0.9%CVE-2021-24935—WP Google Fonts < 3.1.5 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-38335MEDIUMVtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.EPSS 0.9%CVE-2024-29184HIGHFreeScout Stored XSS to Privilege Escalation After CSP BypassEPSS 0.9%CVE-2024-33209MEDIUMFlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" sectioEPSS 0.9%CVE-2026-35052MEDIUMD-Tale affected by Remote Code Execution through redis/shelf storageEPSS 0.9%CVE-2022-29183MEDIUMReflected XSS in GoCDEPSS 0.9%CVE-2022-31175MEDIUMCross-site scripting caused by the editor instance destroying process in ckeditor5EPSS 0.9%CVE-2022-38438MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.9%CVE-2026-31050MEDIUMCross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary codeEPSS 0.9%CVE-2025-34177MEDIUMNetgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site ScriptingEPSS 0.9%CVE-2022-0232MEDIUMUser Registration, Login & Landing Pages – LeadMagic <= 1.2.7 Admin+ Stored Cross-Site ScriptingEPSS 0.9%CVE-2024-37888MEDIUMThe Open Link CKEditor plugin has a cross-site scripting (XSS) vulnerability in open link functionalityEPSS 0.9%CVE-2021-29107MEDIUMThere is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below.EPSS 0.9%