Weaknesses of type CWE-79

28,832 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2026-3001MEDIUMGutenverse <= 3.4.6 - Reflected Cross-Site Scripting via 's' ParameterEPSS 0.6%CVE-2017-0891—Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilitiEPSS 0.6%CVE-2021-24612—Sociable <= 4.3.4.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-24722—Restaurant Menu by MotoPress < 2.4.2 - Admin+ Stored Cross Site ScriptingEPSS 0.6%CVE-2026-73043CRITICALSiYuan before v3.7.4 Remote Code Execution via Template CalculationEPSS 0.6%CVE-2018-10726MEDIUMA stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this rEPSS 0.6%CVE-2023-30790MEDIUMMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relatEPSS 0.6%CVE-2021-38407MEDIUMDelta Electronics DIALinkEPSS 0.6%CVE-2025-49557HIGHAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.6%CVE-2023-4422MEDIUMCross-site Scripting (XSS) - Stored in cockpit-hq/cockpitEPSS 0.6%CVE-2024-3526LOWCampcodes Online Event Management System index.php cross site scriptingEPSS 0.6%CVE-2021-22676—UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScrEPSS 0.6%CVE-2023-29049MEDIUMThe "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromisedEPSS 0.6%CVE-2022-45387MEDIUMJenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in aEPSS 0.6%CVE-2018-0220—A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduEPSS 0.6%CVE-2020-36709MEDIUMPage Builder: KingComposer < 2.9.4 - Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-0256MEDIUMCross-site Scripting (XSS) - Stored in pimcore/pimcoreEPSS 0.6%CVE-2021-27911HIGHXSS vulnerability on contacts viewEPSS 0.6%CVE-2024-4512LOWSourceCodester Prison Management System edit-profile.php cross site scriptingEPSS 0.6%CVE-2023-22464MEDIUMViewVC XSS vulnerability in revision view changed path "copyfrom" locationsEPSS 0.6%