Weaknesses of type CWE-79

28,759 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-25825HIGHZoneMinder contains Cross-site Scripting via log viewingEPSS 0.7%CVE-2025-55143MEDIUMReflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway beforeEPSS 0.7%CVE-2024-22411MEDIUMCross site scripting in Action messages on AvoEPSS 0.7%CVE-2018-15641MEDIUMCross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authEPSS 0.7%CVE-2019-5458—Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execEPSS 0.7%CVE-2022-2028HIGHCross-site Scripting (XSS) - Generic in kromitgmbh/titraEPSS 0.7%CVE-2022-2026HIGHCross-site Scripting (XSS) - Stored in kromitgmbh/titraEPSS 0.7%CVE-2021-32857MEDIUMCockpit vulnerable to Cross-site ScriptingEPSS 0.7%CVE-2019-5457—Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execuEPSS 0.7%CVE-2022-38106MEDIUMCross-Site Scripting Vulnerability in Serv-U Web ClientEPSS 0.7%CVE-2022-31038MEDIUMXSS vulnerability in repository issue list in GogsEPSS 0.7%CVE-2022-2029HIGHCross-site Scripting (XSS) - DOM in kromitgmbh/titraEPSS 0.7%CVE-2022-22124MEDIUMHalo CMS - Stored Cross-Site Scripting (XSS) in Profile ImageEPSS 0.7%CVE-2021-41101MEDIUMCORS `Access-Control-Allow-Origin` settings are too lenientEPSS 0.7%CVE-2024-38503LOWApache Syncope: HTML tags can be injected into Console or Enduser text fieldsEPSS 0.7%CVE-2023-26149MEDIUMVersions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, viaEPSS 0.7%CVE-2022-2861MEDIUMInappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install EPSS 0.7%CVE-2021-28161—In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injEPSS 0.7%CVE-2022-24386HIGHStored XSS in SmarterTrack v100.0.8019.14010EPSS 0.7%CVE-2022-22123MEDIUMHalo CMS - Stored Cross-Site Scripting (XSS) in Article's TitleEPSS 0.7%