Weaknesses of type CWE-79

28,820 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-24246—WorkScout Core < 1.3.4 - Authenticated Stored XSS & XFSEPSS 0.7%CVE-2022-1503LOWGetSimple CMS Content Module edit.php cross site scriptingEPSS 0.7%CVE-2021-24334—Instant Images WordPress Plugin < 4.4.0.1 - Authenticated Stored XSS & XFSEPSS 0.7%CVE-2021-3862MEDIUMCross-site Scripting (XSS) - Reflected in icecoder/icecoderEPSS 0.7%CVE-2021-24386—WP SVG Images < 3.4 - Authenticated (author+) Stored XSS via SVGEPSS 0.7%CVE-2023-6790HIGHPAN-OS: DOM-Based Cross-Site Scripting (XSS) Vulnerability in the Web InterfaceEPSS 0.7%CVE-2023-40290HIGHAn issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects IntEPSS 0.7%CVE-2021-21434LOWXSS in Survey ModuleEPSS 0.7%CVE-2022-27859MEDIUMWordPress Travel Management plugin <= 2.0 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.7%CVE-2022-2115—Popup Anything < 2.1.7 - Reflected Cross-Site ScriptingEPSS 0.7%CVE-2020-5223MEDIUMPersistent XSS vulnerability in filename of attached file in PrivateBinEPSS 0.7%CVE-2021-24208—WP Page Builder < 1.2.4 - Multiple Stored Cross-Site scripting (XSS)EPSS 0.7%CVE-2022-4502HIGHCross-site Scripting (XSS) - Reflected in openemr/openemrEPSS 0.7%CVE-2024-28089MEDIUMHitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity (who has access to the router admin panelEPSS 0.7%CVE-2022-45380MEDIUMJenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resEPSS 0.7%CVE-2021-24129—Themify Portfolio Post < 1.1.6 - Authenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2024-1707MEDIUMGARO WALLBOX GLB+ T2EV7 Software Update index.jsp#settings cross site scriptingEPSS 0.7%CVE-2023-24686MEDIUMAn issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV filEPSS 0.7%CVE-2026-25743HIGHOpenEMR has Stored XSS in Questionnaire answersEPSS 0.7%CVE-2022-29887HIGHCross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentiEPSS 0.7%