Weaknesses of type CWE-79

28,695 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-36171MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-36168MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2021-36092MEDIUMXSS attack using special link in emailEPSS 0.7%CVE-2024-26093MEDIUMAdobe Experience Manager | Cross-site Scripting (Reflected XSS) (CWE-79)EPSS 0.7%CVE-2026-41043MEDIUMApache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queuesEPSS 0.7%CVE-2022-35224—SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting inEPSS 0.7%CVE-2021-43657MEDIUMA Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remotEPSS 0.7%CVE-2020-3460MEDIUMCisco Data Center Network Manager Cross-Site Scripting VulnerabilityEPSS 0.7%CVE-2022-31133MEDIUMCross site scripting in HumHubEPSS 0.7%CVE-2021-1158MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Stored Cross-Site Scripting VulnerabilitiesEPSS 0.7%CVE-2021-32616HIGHImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in 1CDNEPSS 0.7%CVE-2021-1151MEDIUMCisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Stored Cross-Site Scripting VulnerabilitiesEPSS 0.7%CVE-2021-36845MEDIUMYITH Maintenance Mode (WordPress plugin) <= 1.3.8 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.7%CVE-2020-8160—MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via EPSS 0.7%CVE-2026-41610MEDIUMVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2026-86712HIGHSiYuan before 3.8.2 Remote Code Execution via ClipboardEPSS 0.7%CVE-2022-0698MEDIUMMicroweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' parameter.EPSS 0.7%CVE-2023-3837LOWDedeBIZ sys_sql_query.php cross site scriptingEPSS 0.7%CVE-2024-33893MEDIUMCosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to imEPSS 0.7%CVE-2022-45150MEDIUMA reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied EPSS 0.7%