Weaknesses of type CWE-79

28,691 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2017-6511MEDIUMandrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in appEPSS 0.7%CVE-2024-44778HIGHA reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execuEPSS 0.7%CVE-2022-22229HIGHParagon Active Assurance (Formerly Netrounds): Stored Cross-site Scripting (XSS) vulnerability in web administrationEPSS 0.7%CVE-2024-27838MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17EPSS 0.7%CVE-2024-40506HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitalitEPSS 0.7%CVE-2022-22748MEDIUMMalicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL prEPSS 0.7%CVE-2022-2589MEDIUMCross-site Scripting (XSS) - Reflected in beancount/favaEPSS 0.7%CVE-2024-2692CRITICALSiYuan 3.0.3 - RCE via Server Side XSSEPSS 0.7%CVE-2019-15618—Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.EPSS 0.7%CVE-2022-1938—Awin Data Feed < 1.8 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-42547MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Out-of-the-BoxEPSS 0.7%CVE-2021-42549MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Lets-BoxEPSS 0.7%CVE-2021-42548MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Share-one-DriveEPSS 0.7%CVE-2021-42546MEDIUMReflected XSS in search functionality of WP Cloud Plugins - Use-Your-DriveEPSS 0.7%CVE-2026-32626CRITICALAnythingLLM has a Streaming Phase XSS to RCE via LLM Response InjectionEPSS 0.7%CVE-2026-88057MEDIUMAngular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compilerEPSS 0.7%CVE-2021-24794—Connections Business Directory < 10.4.3 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-28599MEDIUMZoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentiaEPSS 0.7%CVE-2025-47110HIGHAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2022-4710MEDIUMRoyal Elementor Addons <= 1.3.59 - Reflected Cross-Site ScriptingEPSS 0.7%