Weaknesses of type CWE-79

28,832 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-35251MEDIUMA cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an adversary is able to mEPSS 0.6%CVE-2023-23636MEDIUMIn Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from tEPSS 0.6%CVE-2026-73043CRITICALSiYuan before v3.7.4 Remote Code Execution via Template CalculationEPSS 0.6%CVE-2021-24622—WP Ticket < 5.10.4 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-40312MEDIUMReflected XSS in multiple JSP files in opennms/opennmsEPSS 0.6%CVE-2021-24722—Restaurant Menu by MotoPress < 2.4.2 - Admin+ Stored Cross Site ScriptingEPSS 0.6%CVE-2025-2767HIGHArista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution VulnerabilityEPSS 0.6%CVE-2021-24793—WPeMatico RSS Feed Fetcher < 2.6.12 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2018-3716—simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.EPSS 0.6%CVE-2026-3001MEDIUMGutenverse <= 3.4.6 - Reflected Cross-Site Scripting via 's' ParameterEPSS 0.6%CVE-2021-24740—Tutor LMS < 1.9.9 - Multiple Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-30790MEDIUMMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relatEPSS 0.6%CVE-2024-26057MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2023-30787MEDIUMMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/introEPSS 0.6%CVE-2025-22270HIGHStored XSS in CyberArk Endpoint Privilege ManagerEPSS 0.6%CVE-2021-24612—Sociable <= 4.3.4.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-86483MEDIUMIn JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possibleEPSS 0.6%CVE-2021-38403MEDIUMDelta Electronics DIALinkEPSS 0.6%CVE-2018-10726MEDIUMA stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this rEPSS 0.6%CVE-2017-0891—Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilitiEPSS 0.6%