Weaknesses of type CWE-79

28,767 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-21398MEDIUMPossible XSS injection through DataColumn Grid classEPSS 0.7%CVE-2024-43744MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-43749MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-43734MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-43747MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-43743MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2022-41239MEDIUMJenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying theEPSS 0.7%CVE-2023-48701HIGHStatamic CMS vulnerable to Cross-site Scripting via uploaded assetsEPSS 0.7%CVE-2026-56397CRITICALSiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and READMEEPSS 0.7%CVE-2021-3529—A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML docuEPSS 0.7%CVE-2021-42365MEDIUMAsgaros Forums <= 1.15.13 Authenticated Stored XSSEPSS 0.7%CVE-2022-2342HIGHCross-site Scripting (XSS) - Stored in outline/outlineEPSS 0.7%CVE-2022-45408MEDIUMThrough a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification pEPSS 0.7%CVE-2022-0375MEDIUMCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchatEPSS 0.7%CVE-2021-32818HIGHRemote code execution and Reflected cross site scripting in haml-coffeeEPSS 0.7%CVE-2018-14520MEDIUMAn issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web EPSS 0.7%CVE-2021-25026—Patreon WordPress < 1.8.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-25761MEDIUMJenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored EPSS 0.7%CVE-2015-20106—ClickBank Affiliate Ads <= 1.20 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2026-34686HIGHAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%