Weaknesses of type CWE-79

28,650 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2019-19002MEDIUMABB eSOMS X-XSS-Protection not enabledEPSS 0.8%CVE-2020-7481—A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All veEPSS 0.8%CVE-2024-4023HIGHStored XSS in flatpressblog/flatpressEPSS 0.8%CVE-2021-36713MEDIUMCross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary code via the sBaseNameEPSS 0.8%CVE-2021-24338—Pods < 2.7.27 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.8%CVE-2022-24873MEDIUMNon-Stored Cross-site Scripting in Shopware storefrontEPSS 0.8%CVE-2021-32793MEDIUMStored XSS Vulnerability in the Pi-hole WebinterfaceEPSS 0.8%CVE-2020-14333MEDIUMA flaw was found in Ovirt Engine's web interface in ovirt 4.4 and earlier, where it did not filter user-controllable parameters completely, EPSS 0.8%CVE-2024-52520MEDIUMNextcloud Server's link reference provider can be tricked into downloading bigger files than intendedEPSS 0.8%CVE-2022-2113HIGHCross-site Scripting (XSS) - Stored in inventree/inventreeEPSS 0.8%CVE-2026-65605CRITICALSiYuan before v3.7.2 Stored XSS to RCE via Attribute ViewEPSS 0.8%CVE-2022-1928MEDIUMCross-site Scripting (XSS) - Stored in go-gitea/giteaEPSS 0.8%CVE-2021-3983MEDIUMCross-site Scripting (XSS) - Stored in kevinpapst/kimai2EPSS 0.8%CVE-2018-0208—A vulnerability in the web-based management interface of the (cloud based) Cisco Registered Envelope Service could allow an authenticated, rEPSS 0.8%CVE-2026-65606CRITICALSiYuan before v3.7.2 Cross-Site Scripting to RCEEPSS 0.8%CVE-2021-3863MEDIUMCross-site Scripting (XSS) - Generic in snipe/snipe-itEPSS 0.8%CVE-2022-24869MEDIUMCross Site Scripting in GLPIEPSS 0.8%CVE-2024-39024HIGHIn Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.EPSS 0.8%CVE-2023-1912HIGHLimit Login Attempts <= 1.7.1 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.8%CVE-2019-5471—An input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent XSSEPSS 0.8%