Weaknesses of type CWE-79

28,671 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2020-15274MEDIUMStored XSS via search result in Wiki.jsEPSS 0.8%CVE-2024-31650CRITICALA cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML viaEPSS 0.8%CVE-2018-19951—If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP SystemEPSS 0.8%CVE-2018-16474—A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.EPSS 0.8%CVE-2025-51502MEDIUMReflected Cross-Site Scripting (XSS) in Microweber CMS 2.0 via the layout parameter on the /admin/page/create page allows arbitrary JavaScriEPSS 0.8%CVE-2021-4108MEDIUMCross-site Scripting (XSS) - Stored in snipe/snipe-itEPSS 0.8%CVE-2021-4121MEDIUMCross-site Scripting (XSS) - Stored in yetiforcecompany/yetiforcecrmEPSS 0.8%CVE-2020-1696MEDIUMA flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, eEPSS 0.8%CVE-2022-34322CRITICALMultiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the conteEPSS 0.8%CVE-2022-35739MEDIUMPRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary conteEPSS 0.8%CVE-2019-15586—A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.EPSS 0.8%CVE-2024-34241MEDIUMA cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admiEPSS 0.8%CVE-2022-36965MEDIUMStored and DOM XSS in QoE Applications: Orion PlatformEPSS 0.8%CVE-2021-24504—WP LMS <= 1.1.2 - Stored Cross-Site Scripting (XSS)EPSS 0.8%CVE-2022-28716HIGHOn 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5,EPSS 0.8%CVE-2024-6050MEDIUMReflected XSS in SOWA OPACEPSS 0.8%CVE-2023-36800HIGHDynamics Finance and Operations Cross-site Scripting VulnerabilityEPSS 0.8%CVE-2023-31584MEDIUMGitHub repository cu/silicon commit a9ef36 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the User InputEPSS 0.8%CVE-2021-44478—A vulnerability has been identified in Polarion ALM (All versions < V21 R2 P2), Polarion WebClient for SVN (All versions). A cross-site scriEPSS 0.8%CVE-2024-40512HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMReporting.EPSS 0.8%