Weaknesses of type CWE-79

28,644 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2017-6053—A Cross-Site Scripting issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A cross-site scripting vulnerability may allow JEPSS 0.8%CVE-2018-7508—A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is iEPSS 0.8%CVE-2022-1330CRITICALstored xss due to unsantized anchor url in alvarotrigo/fullpage.jsEPSS 0.8%CVE-2021-43446MEDIUMONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the document editor allows malEPSS 0.8%CVE-2021-24983—Asset CleanUp < 1.3.8.5 - Reflected Cross-Site Scripting via AJAX ActionEPSS 0.8%CVE-2021-23037—On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists iEPSS 0.8%CVE-2021-43853HIGHCross-Site Scripting in AjaxNetProfessionalEPSS 0.8%CVE-2024-41819HIGHNote Mark has a stored XSS in the note link href attributeEPSS 0.8%CVE-2021-1463MEDIUMCisco Unified Intelligence Center Reflected Cross-Site Scripting VulnerabilityEPSS 0.8%CVE-2021-24297—Goto < 2.1 - Reflected Cross-Site Scripting (XSS)EPSS 0.8%CVE-2024-6753HIGHSocial Auto Poster <= 5.3.14 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.8%CVE-2021-24136—Testimonials Widget < 4.0.0 - Multiple Authenticated Stored XSSEPSS 0.8%CVE-2020-4061LOWCross-site Scripting in OctoberPotential self-XSS when pasting content from malicious websitesEPSS 0.8%CVE-2024-12883MEDIUMcode-projects Job Recruitment _email.php cross site scriptingEPSS 0.8%CVE-2022-42967HIGHXSS in Caret markdown editor leads to remote code execution when viewing crafted Markdown filesEPSS 0.8%CVE-2023-2660MEDIUMSourceCodester Online Computer and Laptop Store view_categories.php sql injectionEPSS 0.8%CVE-2022-43117MEDIUMSourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabiEPSS 0.8%CVE-2015-9105—Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0EPSS 0.8%CVE-2021-39202HIGHWordPress 5.8 beta: Stored Cross-Site Scripting (XSS) vulnerability in widgetEPSS 0.8%CVE-2023-22933HIGHPersistent Cross-Site Scripting through the ‘module’ Tag in a View in Splunk EnterpriseEPSS 0.8%