Weaknesses of type CWE-79

28,669 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2025-51501MEDIUMReflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows executionEPSS 0.8%CVE-2022-1988MEDIUMCross-site Scripting (XSS) - Generic in neorazorx/facturascriptsEPSS 0.8%CVE-2021-36875MEDIUMWordPress uListing plugin <= 2.0.5 - Auth. Reflected Cross-Site Scripting (XSS) vulnerabilityEPSS 0.8%CVE-2021-3646MEDIUMCross-site Scripting (XSS) - Reflected in btcpayserver/btcpayserverEPSS 0.8%CVE-2025-25001MEDIUMMicrosoft Edge for iOS Spoofing VulnerabilityEPSS 0.8%CVE-2018-16480—A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanEPSS 0.8%CVE-2024-42852MEDIUMCross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php EPSS 0.8%CVE-2022-2532—Feed Them Social < 3.0.1 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2024-42346HIGHStored Cross Site Scripting (Stored XSS) in GalaxyEPSS 0.8%CVE-2022-31192HIGHCross Site Scripting possible in DSpace JSPUI "Request a Copy" featureEPSS 0.8%CVE-2024-39031MEDIUMIn Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite othEPSS 0.8%CVE-2024-56527HIGHAn issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.EPSS 0.8%CVE-2020-10041—A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A stored EPSS 0.8%CVE-2022-40088MEDIUMSimple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_websitEPSS 0.8%CVE-2019-25140HIGHComing Soon Page & Maintenance Mode <= 1.8.1 - Stored Cross Site ScriptingEPSS 0.8%CVE-2022-0957HIGHStored XSS via File Upload in star7th/showdocEPSS 0.8%CVE-2022-4839HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.8%CVE-2022-0370HIGHCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchatEPSS 0.8%CVE-2022-1514CRITICALStored XSS via upload plugin functionality in zip format in neorazorx/facturascriptsEPSS 0.8%CVE-2020-2493—Cross-site Scripting Vulnerability in Multimedia ConsoleEPSS 0.8%