Weaknesses of type CWE-79

28,640 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2019-9542—Telos Automated Message Handling System reflected XSS in itemlookup.aspEPSS 0.8%CVE-2023-3084HIGHCross-site Scripting (XSS) - Stored in nilsteampassnet/teampassEPSS 0.8%CVE-2019-9539—Telos Automated Message Handling System reflected XSS in ModalWindowPopup.aspEPSS 0.8%CVE-2020-3579MEDIUMCisco SD-WAN vManage Software Cross-Site Scripting VulnerabilityEPSS 0.8%CVE-2019-15619—Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0.3 and Nextcloud DecEPSS 0.8%CVE-2020-3136MEDIUMCisco Jabber Guest Cross-Site Scripting VulnerabilityEPSS 0.8%CVE-2020-3137MEDIUMCisco Email Security Appliance Cross-Site Scripting VulnerabilityEPSS 0.8%CVE-2022-28770—Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a EPSS 0.8%CVE-2024-42831MEDIUMA reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaEPSS 0.8%CVE-2024-51229HIGHCross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management fEPSS 0.8%CVE-2022-2407—WP phpMyAdmin < 5.2.0.4 - Admin+ Stored Cross-Site ScriptingEPSS 0.8%CVE-2019-18249—Reliable Controls MACH-ProWebCom/Sys, all versions prior to 2.15 (Firmware versions prior to 8.26.4), may allow attacker to execute commandsEPSS 0.8%CVE-2025-5127MEDIUMTeledyne FLIR AX8 prod.php cross site scriptingEPSS 0.8%CVE-2021-33387CRITICALCross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.EPSS 0.8%CVE-2023-39515MEDIUMStored Cross-site Scripting on data_debug.php datasource path view in CactiEPSS 0.8%CVE-2022-0964HIGHStored XSS viva .webmv file upload in star7th/showdocEPSS 0.8%CVE-2024-31443MEDIUMCacti XSS vulnerability in lib/html_tree.php by reading dirty data stored in databaseEPSS 0.8%CVE-2023-47684HIGHWordPress Essential Grid Plugin <= 3.1.0 is vulnerable to Cross Site Scripting (XSS)EPSS 0.8%CVE-2023-33732MEDIUMCross Site Scripting (XSS) in the New Policy form in Microworld Technologies eScan management console 14.0.1400.2281 allows a remote attackeEPSS 0.8%CVE-2022-29168CRITICALCross Site Scripting in Wire MessagesEPSS 0.8%