Weaknesses of type CWE-79

28,456 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-24300PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)EPSS 10.6%CVE-2021-31558MEDIUMDelta Electronics DIAEnergie (Update A)EPSS 10.6%CVE-2021-24287Select All Categories and Taxonomies < 1.3.2 - Reflected Cross-Site Scripting (XSS)EPSS 10.4%CVE-2021-24169Advanced Order Export For WooCommerce < 3.1.8 - Reflected Cross-Site Scripting (XSS)EPSS 10.3%CVE-2021-21802CRITICALThis vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially craftEPSS 9.9%CVE-2025-34174MEDIUMNetgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site ScriptingEPSS 9.8%CVE-2025-41752HIGHReflected XSS vulnerability in pxc_portSfp.phpEPSS 9.8%CVE-2025-41751HIGHReflected XSS vulnerability in pxc_portCntr.phpEPSS 9.8%CVE-2025-41750HIGHReflected XSS vulnerability in pxc_PortCfg.phpEPSS 9.8%CVE-2025-41747HIGHReflected XSS vulnerability in pxc_vlanIntfCfg.phpEPSS 9.8%CVE-2025-41746HIGHReflected XSS vulnerability in pxc_portSecCfg.phpEPSS 9.8%CVE-2025-41748HIGHReflected XSS vulnerability in pxc_Dot1xCfg.phpEPSS 9.8%CVE-2023-37979HIGHWordPress Ninja Forms Plugin <= 3.6.25 is vulnerable to Cross Site Scripting (XSS)EPSS 9.7%CVE-2025-9816HIGHWP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent HeaderEPSS 9.7%CVE-2019-10241In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote clEPSS 9.6%CVE-2021-29625HIGHXSS in doc_linkEPSS 9.6%CVE-2021-44544HIGHDelta Electronics DIAEnergie (Update A)EPSS 9.5%CVE-2023-29442MEDIUMZoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.EPSS 9.4%CVE-2022-0734MEDIUMA cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FEPSS 9.4%CVE-2023-38501MEDIUMcopyparty vulnerable to reflected cross-site scripting via k304 parameterEPSS 9.2%