Weaknesses of type CWE-79

28,777 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-0325MEDIUMUvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the applEPSS 0.7%CVE-2022-1909CRITICALCross-site Scripting (XSS) - Stored in causefx/organizrEPSS 0.7%CVE-2024-52552HIGHJenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resEPSS 0.7%CVE-2016-10537—backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your REPSS 0.7%CVE-2021-24900—Ninja Tables < 4.1.8 - Admin+ Stored Cross-Site Cross-Site ScriptingEPSS 0.7%CVE-2023-38359MEDIUMIBM Cognos Analytics cross-site scriptingEPSS 0.7%CVE-2023-24494MEDIUMA stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning itEPSS 0.7%CVE-2022-38220MEDIUMAn XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary wEPSS 0.7%CVE-2025-46812LOWTrix vulnerable to Cross-site Scripting on copy & pasteEPSS 0.7%CVE-2026-15094MEDIUMWP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' ParameterEPSS 0.7%CVE-2024-3541LOWCampcodes Church Management System admin_user.php cross site scriptingEPSS 0.7%CVE-2024-7982CRITICALRegistrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSSEPSS 0.7%CVE-2025-10370MEDIUMMiczFlor RPi-Jukebox-RFID userScripts.php cross site scriptingEPSS 0.7%CVE-2022-46391MEDIUMAWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.EPSS 0.7%CVE-2024-1935HIGHGiveaways and Contests by RafflePress <= 1.12.5 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-22181HIGHJunos OS: J-Web can be compromised through reflected XSS attacksEPSS 0.7%CVE-2020-14320—In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.EPSS 0.7%CVE-2023-28313MEDIUMMicrosoft Dynamics 365 Customer Voice Cross-Site Scripting VulnerabilityEPSS 0.7%CVE-2022-50905MEDIUMe107 CMS v3.2.1 - Reflected XSS via Comment FlowEPSS 0.7%CVE-2021-24871—Get Custom Field Values < 4.0.1 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%