Weaknesses of type CWE-79

28,677 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-20085MEDIUMA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 0.7%CVE-2019-10180LOWA vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parametEPSS 0.7%CVE-2026-73415HIGHjupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tabEPSS 0.7%CVE-2023-51504MEDIUMWordPress Dan's Embedder for Google Calendar Plugin <= 1.2 is vulnerable to Cross Site Scripting (XSS)EPSS 0.7%CVE-2023-34089HIGHDecidim Cross-site Scripting vulnerability in the processes filterEPSS 0.7%CVE-2024-52762MEDIUMA cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbEPSS 0.7%CVE-2021-37710HIGHCross-Site Scripting via SVG media filesEPSS 0.7%CVE-2021-39169HIGHXSS vulnerability using dialogEPSS 0.7%CVE-2022-0956HIGHStored XSS via File Upload in star7th/showdocEPSS 0.7%CVE-2025-48954HIGHDiscourse vulnerable to XSS via user-provided query parameter in oauth failure flowEPSS 0.7%CVE-2021-32713MEDIUMAuthenticated Stored XSSEPSS 0.7%CVE-2022-42225MEDIUMJumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can eEPSS 0.7%CVE-2026-53963HIGHDiscourse: Stored-XSS in 2FA delete confirmation modalEPSS 0.7%CVE-2022-43569HIGHPersistent Cross-Site Scripting via a Data Model object name in Splunk EnterpriseEPSS 0.7%CVE-2021-24152—Popup Builder < 3.74 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2022-22182HIGHJunos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web sessionEPSS 0.7%CVE-2022-1291HIGHXSS vulnerability with default `onCellHtmlData` function in hhurz/tableexport.jquery.pluginEPSS 0.7%CVE-2024-24570HIGHStatamic account takeover via XSS and password reset linkEPSS 0.7%CVE-2024-11387MEDIUMEasy Liveblogs <= 2.3.5 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-40190HIGHSAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequateEPSS 0.7%