Weaknesses of type CWE-79

28,664 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-1268—Donate Extra <= 2.02 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2022-1220—FoxyShop < 4.8.2 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2021-1271MEDIUMCisco Web Security Appliance Stored Cross-Site Scripting VulnerabilityEPSS 0.8%CVE-2021-21283MEDIUMXSS in Flarum Sticky extension.EPSS 0.8%CVE-2017-9556—Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authenticated atEPSS 0.8%CVE-2024-42366CRITICALVR Overlay RCEEPSS 0.8%CVE-2024-23786CRITICALCross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a neEPSS 0.8%CVE-2021-26628HIGHMaxBoard XSS and File Upload VulnerabilityEPSS 0.8%CVE-2021-21418MEDIUMPotential XSS injection in the newsletter conditions fieldEPSS 0.8%CVE-2018-5411—Pixar's Tractor software, versions 2.2 and earlier, contains a stored cross-site scripting vulnerabilityEPSS 0.8%CVE-2022-0926HIGHFile upload filter bypass leading to stored XSS in microweber/microweberEPSS 0.8%CVE-2019-3761MEDIUMThe RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a stored cross-sEPSS 0.8%CVE-2019-19003MEDIUMABB eSOMS: HTTPOnly flag not setEPSS 0.8%CVE-2022-31191HIGHCross Site Scripting possible in DSpace JSPUI spellcheck and autocomplete toolsEPSS 0.8%CVE-2023-39511MEDIUMStored Cross-Site-Scripting on reports_admin.php device name in CactiEPSS 0.8%CVE-2021-4176MEDIUMCross-site Scripting (XSS) - Reflected in livehelperchat/livehelperchatEPSS 0.8%CVE-2017-7427MEDIUMiManager - Multiple Reflected Cross-Site Scripting attacksEPSS 0.8%CVE-2023-31285MEDIUMAn XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings EPSS 0.8%CVE-2026-70355HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2023-1036MEDIUMSourceCodester Dental Clinic Appointment Reservation System POST Parameter signup.php cross site scriptingEPSS 0.8%