Weaknesses of type CWE-79

28,694 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-40510HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmEPSS 0.7%CVE-2021-24474—Awesome Weather Widget <= 3.0.2 - Reflected Cross-site Scripting (XSS)EPSS 0.7%CVE-2026-34448CRITICALSiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execution in the desktop clientEPSS 0.7%CVE-2021-24560—Software License Manager < 4.4.8 - Reflected Cross-Site ScriptingEPSS 0.7%CVE-2025-47852MEDIUMIn JetBrains TeamCity before 2025.03.2 stored XSS via YouTrack integration was possibleEPSS 0.7%CVE-2021-41142MEDIUMXSS via the name of a deleted attachmentEPSS 0.7%CVE-2023-28439MEDIUMckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying processEPSS 0.7%CVE-2023-26449MEDIUMThe "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executeEPSS 0.7%CVE-2023-26450MEDIUMThe "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executEPSS 0.7%CVE-2020-26227MEDIUMCross-Site Scripting in Fluid view helpersEPSS 0.7%CVE-2024-1602HIGHStored XSS leading to RCE in parisneo/lollms-webuiEPSS 0.7%CVE-2022-1719MEDIUMReflected XSS on ticket filter function in polonel/trudeskEPSS 0.7%CVE-2022-2775—Fast Flow < 1.2.13 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-4609HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.7%CVE-2020-3591MEDIUMCisco SD-WAN vManage Cross-Site Scripting VulnerabilityEPSS 0.7%CVE-2020-12512HIGHPepper+Fuchs Comtrol IO-Link Master Cross-Site ScriptingEPSS 0.7%CVE-2022-0857MEDIUMePO Reflected Cross-site scripting vulnerabilityEPSS 0.7%CVE-2023-2835MEDIUMWP Directory Kit <= 1.2.3 - Reflected Cross-Site Scripting via 'search'EPSS 0.7%CVE-2026-50758HIGHCross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp paraEPSS 0.7%CVE-2021-1254MEDIUMCisco Finesse Cross-Site Scripting VulnerabilitiesEPSS 0.7%