Weaknesses of type CWE-79

28,639 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-20293—A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly hEPSS 0.9%CVE-2025-54141HIGHViewVC's standalone server exposes arbitrary server filesystem contentEPSS 0.9%CVE-2022-0526HIGHCross-site Scripting (XSS) - Stored in chatwoot/chatwootEPSS 0.9%CVE-2021-29107MEDIUMThere is a stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below.EPSS 0.9%CVE-2022-0232MEDIUMUser Registration, Login & Landing Pages – LeadMagic <= 1.2.7 Admin+ Stored Cross-Site ScriptingEPSS 0.9%CVE-2021-24599—Email Encoder < 2.1.2 - Reflected Cross Site ScriptingEPSS 0.9%CVE-2023-2507CRITICALCleverTap Cordova Plugin 2.6.2 - Reflected XSSEPSS 0.9%CVE-2024-25411MEDIUMA cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadEPSS 0.9%CVE-2019-1802—Cisco Firepower Management Center Persistent Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2023-23922—Moodle: reflected xss risk in blog searchEPSS 0.9%CVE-2026-17505MEDIUMTranslatePress <= 3.2.5 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-0268HIGHJunos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks.EPSS 0.9%CVE-2024-11004MEDIUMReflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticaEPSS 0.9%CVE-2022-0352HIGHCross-site Scripting (XSS) - Reflected in janeczku/calibre-webEPSS 0.9%CVE-2022-1584MEDIUMReflected XSS in microweber/microweberEPSS 0.9%CVE-2022-29882HIGHA vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not handle uploaded files correctly. An unauthentiEPSS 0.9%CVE-2023-36030MEDIUMMicrosoft Dynamics 365 Sales Spoofing VulnerabilityEPSS 0.9%CVE-2018-18991—Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted UEPSS 0.9%CVE-2022-23073—Recipes - Stored XSS in ClipboardEPSS 0.9%CVE-2022-23058—ERPNext - Stored XSS in My SettingsEPSS 0.9%