Weaknesses of type CWE-79

28,650 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2019-11291LOWRabbitMQ XSS attack via federation and shovel endpointsEPSS 0.8%CVE-2024-54996HIGHMonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parametEPSS 0.8%CVE-2022-0321—WP Voting Contest < 3.0 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2021-24925—Modern Events Calendar Lite < 6.1.5 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2022-21690HIGHCross-Site Scripting in OnionshareEPSS 0.8%CVE-2021-24938—WooCommerce Currency Switcher < 1.3.7.1 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2022-40626MEDIUMReflected XSS in the backurl parameter of Zabbix FrontendEPSS 0.8%CVE-2022-0327—Master Addons for Elementor < 1.8.2 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2020-15162MEDIUMStored XSS in PrestaShopEPSS 0.8%CVE-2026-17532MEDIUMSeraphinite Accelerator <= 2.29.18 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2020-29496MEDIUMDell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user EPSS 0.8%CVE-2015-0749MEDIUMCisco Unified Communications Manager Cross-Site Scripting VulnerabilityEPSS 0.8%CVE-2017-9555—Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inEPSS 0.8%CVE-2022-35230LOWReflected XSS in graphs page of Zabbix FrontendEPSS 0.8%CVE-2025-54534MEDIUMIn JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset pageEPSS 0.8%CVE-2018-7834—A CWE-79 Cross-Site Scripting vulnerability exists in all versions of the TSXETG100 allowing an attacker to send a specially crafted URL witEPSS 0.8%CVE-2021-32962HIGHClaroty Secure Remote Access Site - Authentication Bypass Using an Alternate Path or ChannelEPSS 0.8%CVE-2024-40643CRITICALJoplin has a parsing error leading to Cross-site Scripting (XSS)EPSS 0.8%CVE-2021-33021MEDIUMxArrow SCADA Cross-site ScriptingEPSS 0.8%CVE-2019-19002MEDIUMABB eSOMS X-XSS-Protection not enabledEPSS 0.8%