Weaknesses of type CWE-79

28,666 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2025-50128CRITICALA cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev masteEPSS 0.8%CVE-2021-29116MEDIUMBUG-000142180 Hosted feature services vulnerable to stored XSSEPSS 0.8%CVE-2026-70355HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-46410CRITICALA cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 aEPSS 0.8%CVE-2022-1951—Core Plugin for Kitestudio Themes < 2.3.1 - Reflected Cross-Site-ScriptingEPSS 0.8%CVE-2024-29890HIGHRemote code execution in datalens-uiEPSS 0.8%CVE-2019-15614—Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.EPSS 0.8%CVE-2021-24873—Tutor LMS < 1.9.11 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2021-38357MEDIUMSMS OVH <= 0.1 Reflected Cross-Site ScriptingEPSS 0.8%CVE-2021-24908—Check & Log Email < 1.0.4 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2024-45595MEDIUMD-Tale allows Remote Code Execution through the Query input on Chart BuilderEPSS 0.8%CVE-2022-0877HIGHCross-site Scripting (XSS) - Stored in bookstackapp/bookstackEPSS 0.8%CVE-2020-11055MEDIUMCross-site Scripting in BookStackEPSS 0.8%CVE-2021-38358MEDIUMMoolaMojo <= 0.7.4.1 Reflected Cross-Site ScriptingEPSS 0.8%CVE-2021-4107MEDIUMCross-site Scripting (XSS) - Reflected in yetiforcecompany/yetiforcecrmEPSS 0.8%CVE-2022-42715MEDIUMA reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uEPSS 0.8%CVE-2024-40509HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmEPSS 0.8%CVE-2026-9086HIGHKeycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypassEPSS 0.8%CVE-2024-40785MEDIUMThis issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, mEPSS 0.8%CVE-2025-1359MEDIUMSIAM Industria de Automação e Monitoramento qrcode.jsp cross site scriptingEPSS 0.8%