Weaknesses of type CWE-79

28,773 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-29106MEDIUMThere is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.EPSS 0.7%CVE-2024-2311MEDIUMAvada <= 7.11.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.7%CVE-2025-26202MEDIUMCross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands) in EPSS 0.7%CVE-2020-8263—A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site ScriptinEPSS 0.7%CVE-2026-53427LOWCross-site scripting in MDEx via unescaped highlight_lines_class code-fence attributeEPSS 0.7%CVE-2022-3036—Gettext override translations < 2.0.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-46734MEDIUMSymfony potential Cross-site Scripting vulnerabilities in CodeExtension filtersEPSS 0.7%CVE-2022-43709MEDIUMMyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string viEPSS 0.7%CVE-2020-16246—GE Reason S20 Ethernet SwitchEPSS 0.7%CVE-2024-52552HIGHJenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resEPSS 0.7%CVE-2020-10633—A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attackerEPSS 0.7%CVE-2018-19006—OSIsoft PI Vision, versions PI Vision 2017, and PI Vision 2017 R2, The application contains a cross-site scripting vulnerability where displEPSS 0.7%CVE-2021-24482—Related Posts for WordPress <= 2.0.4 - Authenticated Stored XSS & XFSEPSS 0.7%CVE-2022-0374MEDIUMCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchatEPSS 0.7%CVE-2022-0894HIGHCross-site Scripting (XSS) - Stored in pimcore/pimcoreEPSS 0.7%CVE-2020-10630—SAE IT-systems FW-50 Remote Telemetry Unit (RTU). The software does not neutralize or incorrectly neutralizes user-controllable input beforeEPSS 0.7%CVE-2021-24157—Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Stored Cross Site ScriptingEPSS 0.7%CVE-2022-1909CRITICALCross-site Scripting (XSS) - Stored in causefx/organizrEPSS 0.7%CVE-2026-0533HIGHStored XSS in Fusion desktop when attempting to delete a fileEPSS 0.7%CVE-2023-2304MEDIUMFavorites <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.7%