Weaknesses of type CWE-79

28,756 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-32970HIGHCross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in PhlexEPSS 0.7%CVE-2024-34452MEDIUMCMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document.EPSS 0.7%CVE-2024-29881MEDIUMTinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elementsEPSS 0.7%CVE-2026-47995HIGHAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2019-7621—Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attackeEPSS 0.7%CVE-2025-64675HIGHAzure Cosmos DB Spoofing VulnerabilityEPSS 0.7%CVE-2023-36823HIGHSanitize vulnerable to Cross-site Scripting via insufficient neutralization of `style` element contentEPSS 0.7%CVE-2022-24855HIGHXSS vulnerability in MetabaseEPSS 0.7%CVE-2021-34357MEDIUMReflected XSS Vulnerability in QmailAgentEPSS 0.7%CVE-2022-43409MEDIUMJenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POEPSS 0.7%CVE-2025-27506MEDIUMNocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password PageEPSS 0.7%CVE-2022-1458HIGHStored XSS Leads To Session Hijacking in openemr/openemrEPSS 0.7%CVE-2024-23998MEDIUMgoanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.EPSS 0.7%CVE-2021-43549MEDIUMOSIsoft PI Web APIEPSS 0.7%CVE-2022-27183HIGHReflected XSS in a query parameter of the Monitoring ConsoleEPSS 0.7%CVE-2024-32340CRITICALA cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or EPSS 0.7%CVE-2023-6717MEDIUMKeycloak: xss via assertion consumer service url in saml post-binding flowEPSS 0.7%CVE-2024-0647MEDIUMSparksuite SimpleMDE iFrame cross site scriptingEPSS 0.7%CVE-2022-39350MEDIUM@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability DetailsEPSS 0.7%CVE-2025-55143MEDIUMReflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway beforeEPSS 0.7%