Weaknesses of type CWE-79

28,804 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-2537—WooCommerce PDF Invoices & Packing Slips < 3.0.1 - Reflected Cross-Site ScriptingEPSS 0.7%CVE-2022-35945MEDIUMCross site scripting (XSS) via registration API in GLPIEPSS 0.7%CVE-2024-27306MEDIUMaiohttp vulnerable to XSS on index pages for static file handlingEPSS 0.7%CVE-2024-3084MEDIUMPHPGurukul Emergency Ambulance Hiring Portal Hire an Ambulance Page cross site scriptingEPSS 0.7%CVE-2025-5013MEDIUMHkCms Search index.html cross site scriptingEPSS 0.7%CVE-2024-27104MEDIUMStored XSS in dashboards in GLPIEPSS 0.7%CVE-2024-24135MEDIUMProduct Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSEPSS 0.7%CVE-2023-26445MEDIUMFrontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. MEPSS 0.7%CVE-2023-26446MEDIUMThe users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed EPSS 0.7%CVE-2022-1536LOWautomad Dashboard cross site scriptingEPSS 0.7%CVE-2026-82642HIGHReadest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead to arbitrary code executionEPSS 0.7%CVE-2022-43561MEDIUMPersistent Cross-Site Scripting in “Save Table” Dialog in Splunk EnterpriseEPSS 0.7%CVE-2023-26447MEDIUMThe "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not geEPSS 0.7%CVE-2023-48197MEDIUMCross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cooEPSS 0.7%CVE-2021-32737HIGHXSS Injection in Media Collection Title was possibleEPSS 0.7%CVE-2024-52053HIGHStored Cross-Site Scripting in Wowza Streaming EngineEPSS 0.7%CVE-2023-26448MEDIUMCustom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script EPSS 0.7%CVE-2024-29049MEDIUMMicrosoft Edge (Chromium-based) Webview2 Spoofing VulnerabilityEPSS 0.7%CVE-2021-24315—Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.7%CVE-2021-4103MEDIUMCross-site Scripting (XSS) - Stored in vanessa219/vditorEPSS 0.7%