Weaknesses of type CWE-79

28,677 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-29931HIGHWordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.8%CVE-2024-26092MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.8%CVE-2021-25103—GTranslate < 2.9.7 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2022-1457CRITICALStore XSS in title parameter executing at EditUser Page & EditProducto page in neorazorx/facturascriptsEPSS 0.8%CVE-2021-25102—All In One WP Security < 4.4.11 - Authenticated Reflected Cross-Site ScriptingEPSS 0.8%CVE-2024-25090MEDIUMApache Roller: Insufficient input validation for some user profile and bookmark fields when Roller in untested-users modeEPSS 0.8%CVE-2019-15602—The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (XSS) vulnerability inEPSS 0.8%CVE-2022-40044MEDIUMCentreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at ConfEPSS 0.8%CVE-2022-0942CRITICALStored XSS due to Unrestricted File Upload in star7th/showdocEPSS 0.8%CVE-2019-15603—The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename rendered in a directoryEPSS 0.8%CVE-2024-40508HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConferenceEPSS 0.8%CVE-2023-6650MEDIUMSourceCodester Simple Invoice Generator System login.php cross site scriptingEPSS 0.8%CVE-2021-22723—A CWE-79: Improper Neutralization of Input During Web Page Generation (Cross-siteScripting) through Cross-Site Request Forgery (CSRF) vulnerEPSS 0.8%CVE-2024-40507HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.EPSS 0.8%CVE-2021-20654—Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named EPSS 0.8%CVE-2023-6649MEDIUMPHPGurukul Teacher Subject Allocation Management System index.php cross site scriptingEPSS 0.8%CVE-2023-6297MEDIUMPHPGurukul Nipah Virus Testing Management System Search Report Page patient-search-report.php cross site scriptingEPSS 0.8%CVE-2023-6465MEDIUMPHPGurukul Nipah Virus Testing Management System registered-user-testing.php cross site scriptingEPSS 0.8%CVE-2022-2865HIGHA cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3EPSS 0.8%CVE-2021-44163MEDIUMChain Sea Information Integration Co., Ltd ai chatbot system - Reflected XSSEPSS 0.8%