Weaknesses of type CWE-79

28,677 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-0743HIGHCross-site Scripting (XSS) - Generic in answerdev/answerEPSS 0.7%CVE-2024-13830MEDIUMReflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticaEPSS 0.7%CVE-2024-22191HIGHStored cross-site scripting (XSS) in `key_value` field in AvoEPSS 0.7%CVE-2026-27245CRITICALAdobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)EPSS 0.7%CVE-2026-76200CRITICALAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2021-4363MEDIUMWP Quick FrontEnd Editor <= 5.5 - Reflected Cross-Site ScriptingEPSS 0.7%CVE-2019-25148MEDIUMWP HTML Mail < 2.9.1 - HTML InjectionEPSS 0.7%CVE-2026-34691CRITICALAdobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2026-76201CRITICALAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2022-30536LOWWordPress WP Maintenance plugin <= 6.0.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.7%CVE-2021-29103MEDIUMThere is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.EPSS 0.7%CVE-2026-27246CRITICALAdobe Connect | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.7%CVE-2026-27243CRITICALAdobe Connect | Cross-site Scripting (Reflected XSS) (CWE-79)EPSS 0.7%CVE-2023-5135MEDIUMSimple Cloudflare Turnstile <= 1.23.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.7%CVE-2021-29109MEDIUMA reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9.EPSS 0.7%CVE-2023-1372HIGHWH Testimonials <= 3.0.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2020-13669—Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x verEPSS 0.7%CVE-2023-35153CRITICALXWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parametersEPSS 0.7%CVE-2021-24323—Woocommerce < 5.2.0 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.7%CVE-2024-39248MEDIUMA cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload iEPSS 0.7%