Weaknesses of type CWE-79

28,772 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-36809HIGHKiwi TCMS's misconfigured HTTP headers allow stored XSS execution with FirefoxEPSS 0.7%CVE-2022-24709HIGHCross site scripting in @awsui/components-reactEPSS 0.7%CVE-2022-4271HIGHCross-site Scripting (XSS) - Reflected in osticket/osticketEPSS 0.7%CVE-2025-41393MEDIUMReflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image EPSS 0.7%CVE-2026-4313LOWStored XSS in AdaptiveGRCEPSS 0.7%CVE-2018-16481—A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absEPSS 0.7%CVE-2023-26131MEDIUMAll versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerablEPSS 0.7%CVE-2021-24225—Advanced Booking Calendar < 1.6.7 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2024-27300MEDIUMphpMyFAQ Stored XSS at user emailEPSS 0.7%CVE-2023-4979HIGHCross-site Scripting (XSS) - Reflected in librenms/librenmsEPSS 0.7%CVE-2023-0549LOWYAFNET Private Message PostPrivateMessage cross site scriptingEPSS 0.7%CVE-2024-7644MEDIUMSourceCodester Leads Manager Tool Add Leads add-leads.php cross site scriptingEPSS 0.7%CVE-2021-27436—WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code EPSS 0.7%CVE-2023-4980HIGHCross-site Scripting (XSS) - Generic in librenms/librenmsEPSS 0.7%CVE-2021-34361MEDIUMReflected XSS Vulnerability in Proxy ServerEPSS 0.7%CVE-2021-38680MEDIUMReflected XSS in Kazoo ServerEPSS 0.7%CVE-2023-5485MEDIUMInappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions vEPSS 0.7%CVE-2024-44088MEDIUMApache Geode: Reflected XSSEPSS 0.7%CVE-2024-3542LOWCampcodes Church Management System add_visitor.php cross site scriptingEPSS 0.7%CVE-2021-29106MEDIUMThere is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.EPSS 0.7%