Weaknesses of type CWE-79

28,827 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2025-13418MEDIUMResponsive Pricing Table <= 5.1.12 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24134—Constant Contact Forms < 1.8.8 - Multiple Authenticated Stored XSSEPSS 0.7%CVE-2023-1030MEDIUMSourceCodester/code-projects Online Boat Reservation System POST Parameter login.php cross site scriptingEPSS 0.7%CVE-2024-1269LOWSourceCodester Product Management System supplier.php cross site scriptingEPSS 0.7%CVE-2022-24432MEDIUMICSA-22-062-01 IPCOMM ipDIOEPSS 0.7%CVE-2021-24963—LiteSpeed Cache < 4.4.4 - Admin+ Reflected Cross-Site ScriptingEPSS 0.7%CVE-2021-24127—ThirstyAffiliates < 3.9.3 - Authenticated Stored XSSEPSS 0.7%CVE-2025-41749HIGHReflected XSS vulnerability in port_util.phpEPSS 0.7%CVE-2021-39473MEDIUMSaibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and contact fields.EPSS 0.7%CVE-2025-41745HIGHReflected XSS vulnerability in pxc_portCntr2.phpEPSS 0.7%CVE-2026-33303MEDIUMOpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print ViewEPSS 0.7%CVE-2025-1983MEDIUMStored Cross-Site Scripting in Ready_EPSS 0.7%CVE-2023-27711MEDIUMCross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admiEPSS 0.7%CVE-2020-16218—Philips Patient Monitoring Devices Cross-site ScriptingEPSS 0.7%CVE-2022-3392MEDIUMWP Humans.txt <= 1.0.6 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2026-33299HIGHOpenEMR has Stored XSS in patient encounter Eye Exam form answersEPSS 0.7%CVE-2022-39800—SAP BusinessObjects BI LaunchPad - versions 420, 430, is susceptible to script execution attack by an unauthenticated attacker due to impropEPSS 0.7%CVE-2020-15083MEDIUMReflected XSS when uploading an image in the Product page in PrestaShopEPSS 0.7%CVE-2021-24330—Funnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google Analytics IDEPSS 0.7%CVE-2021-24331—Smooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSSEPSS 0.7%