Weaknesses of type CWE-79

28,677 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-2865HIGHA cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3EPSS 0.8%CVE-2026-0279LOWPAN-OS: Multiple Cross-Site Scripting (XSS) VulnerabilitiesEPSS 0.8%CVE-2026-66882LOWReflected XSS in AshAuthentication confirmation and magic link interaction formsEPSS 0.8%CVE-2021-44163MEDIUMChain Sea Information Integration Co., Ltd ai chatbot system - Reflected XSSEPSS 0.8%CVE-2021-38345HIGHBrizy <= 1.0.125 and 1.0.127 – 2.3.11 Incorrect authorization checks allowing Post modificationEPSS 0.8%CVE-2021-24205—Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box WidgetEPSS 0.8%CVE-2022-24811MEDIUMCross-site Scripting in Combodo iTopEPSS 0.7%CVE-2017-7437MEDIUMCross site scripting attacks against NetIQ Privileged Account ManagerEPSS 0.7%CVE-2024-26089MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.7%CVE-2017-7419MEDIUMNetIQ Access Manager OAuth Consent screen XSS attackEPSS 0.7%CVE-2020-6804HIGHXSS in Mozilla WebThings GatewayEPSS 0.7%CVE-2023-6013CRITICALH2O Local File IncludeEPSS 0.7%CVE-2023-0038HIGHSurvey Maker – Best WordPress Survey Plugin <= 3.1.3 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2024-26090MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.7%CVE-2019-25147HIGHPretty Links <= 2.1.9 - Unauthenticated Stored Cross-Site Scripting via track_linkEPSS 0.7%CVE-2024-44081CRITICALIn Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videEPSS 0.7%CVE-2022-44724HIGHThe Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitraryEPSS 0.7%CVE-2021-24147—Modern Events Calendar Lite < 5.16.5 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.7%CVE-2026-73417HIGHJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)EPSS 0.7%CVE-2023-28309HIGHMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 0.7%