Weaknesses of type CWE-79

28,677 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2020-13669—Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x verEPSS 0.7%CVE-2022-3513MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting from 15.9 before 15.9.EPSS 0.7%CVE-2021-24323—Woocommerce < 5.2.0 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.7%CVE-2022-44449MEDIUMStored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administraEPSS 0.7%CVE-2024-47068MEDIUMDOM Clobbering Gadget found in rollup bundled scripts that leads to XSSEPSS 0.7%CVE-2024-13993MEDIUMNagios XI < 2024R1.1.2 Reflected XSS via Login Page on Older BrowsersEPSS 0.7%CVE-2024-12626CRITICALAutomatorWP <= 5.0.9 - Reflected Cross-Site Scripting via a-0-o-search_field_valueEPSS 0.7%CVE-2024-6807MEDIUMSourceCodester Student Study Center Desk Management System HTTP POST Request Users.php cross site scriptingEPSS 0.7%CVE-2017-14801MEDIUMReflected xss in Admin Console REST interfaceEPSS 0.7%CVE-2017-6864—The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user to perform stored CrEPSS 0.7%CVE-2022-0969—Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-40311MEDIUMStored XSS in multiple JSP files in opennms/opennmsEPSS 0.7%CVE-2024-25344MEDIUMCross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to executEPSS 0.7%CVE-2021-36823MEDIUMWordPress Absolutely Glamorous Custom Admin plugin <= 6.8 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.7%CVE-2025-64537CRITICALAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.7%CVE-2022-0820MEDIUMCross-site Scripting (XSS) - Stored in orchardcms/orchardcoreEPSS 0.7%CVE-2019-5467—An input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent XSS. EPSS 0.7%CVE-2024-29792HIGHWordPress Unlimited Elements for Elementor plugin <= 1.5.93 - Reflected Cross Site Scripting (XSS) vulnerabilityEPSS 0.7%CVE-2023-34408MEDIUMDokuWiki before 2023-04-04a allows XSS via RSS titles.EPSS 0.7%CVE-2019-18233—In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special characters in the error EPSS 0.7%