Weaknesses of type CWE-79

28,827 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-24330—Funnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google Analytics IDEPSS 0.7%CVE-2022-4840HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.7%CVE-2020-15083MEDIUMReflected XSS when uploading an image in the Product page in PrestaShopEPSS 0.7%CVE-2021-24331—Smooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSSEPSS 0.7%CVE-2023-32070CRITICALImproper Neutralization of Script in Attributes in XWiki (X)HTML renderersEPSS 0.7%CVE-2021-45071MEDIUMCross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbEPSS 0.7%CVE-2022-4695HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.7%CVE-2024-55074HIGHThe edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG filEPSS 0.7%CVE-2022-1530LOWCross-site Scripting (XSS) in livehelperchat/livehelperchatEPSS 0.7%CVE-2025-25304MEDIUMVega allows Cross-site Scripting via the vlSelectionTuples functionEPSS 0.7%CVE-2022-31889MEDIUMCross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533EPSS 0.7%CVE-2024-9414HIGHCross-site Scripting vulnerability in LCDS LAquis SCADAEPSS 0.7%CVE-2023-33195MEDIUMCraft CMS XSS in RSS widget feedEPSS 0.7%CVE-2026-39846CRITICALSiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captionsEPSS 0.7%CVE-2024-37304MEDIUMNuGetGallery's Markdown Autolinks Processing Vulnerable to Cross-site ScriptingEPSS 0.7%CVE-2022-23458MEDIUMToast UI Grid vulnerable to Cross-site scriptingEPSS 0.7%CVE-2026-33067MEDIUMSiYuan has Stored XSS to RCE via Unsanitized Bazaar Package MetadataEPSS 0.7%CVE-2024-0611MEDIUMMaster Slider – Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callbackEPSS 0.7%CVE-2021-24682—Cool Tag Cloud < 2.26 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24672—One User Avatar < 2.3.7 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%