Weaknesses of type CWE-79

28,647 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-3950HIGHCross-site Scripting (XSS) - Stored in django-helpdesk/django-helpdeskEPSS 0.8%CVE-2022-23980MEDIUMWordPress Yasr – Yet Another Stars Rating plugin <= 2.9.9 - Cross-Site Scripting (XSS) vulnerabilityEPSS 0.8%CVE-2018-8928MEDIUMCross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated useEPSS 0.8%CVE-2018-8917MEDIUMCross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to injEPSS 0.8%CVE-2022-0911MEDIUMCross-site Scripting (XSS) - Stored in pimcore/pimcoreEPSS 0.8%CVE-2019-11827MEDIUMCross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to injEPSS 0.8%CVE-2018-8918MEDIUMCross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arEPSS 0.8%CVE-2022-0893MEDIUMCross-site Scripting (XSS) - Stored in pimcore/pimcoreEPSS 0.8%CVE-2018-8915MEDIUMCross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to EPSS 0.8%CVE-2018-8924MEDIUMCross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arEPSS 0.8%CVE-2019-11825MEDIUMCross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary EPSS 0.8%CVE-2021-47817MEDIUMOpenEMR 5.0.2.1 - Remote Code ExecutionEPSS 0.8%CVE-2022-28172MEDIUMThe web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient inpuEPSS 0.8%CVE-2024-33111MEDIUMD-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.EPSS 0.8%CVE-2024-26517CRITICALSQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to tEPSS 0.8%CVE-2024-4835HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.8%CVE-2023-2395MEDIUMNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.8%CVE-2023-2396MEDIUMNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.8%CVE-2021-32850MEDIUMjQuery MiniColors vulnerable to Cross-site ScriptingEPSS 0.8%CVE-2019-15969MEDIUMCisco Web Security Appliance Management Interface Cross-Site Scripting VulnerabilityEPSS 0.8%