Weaknesses of type CWE-79

28,832 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-0523MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 15.6 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1EPSS 0.6%CVE-2022-0243HIGHCross-site Scripting (XSS) - Stored in orchardcms/orchardcoreEPSS 0.6%CVE-2020-36709MEDIUMPage Builder: KingComposer < 2.9.4 - Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-5060HIGHCross-site Scripting (XSS) - DOM in librenms/librenmsEPSS 0.6%CVE-2024-4512LOWSourceCodester Prison Management System edit-profile.php cross site scriptingEPSS 0.6%CVE-2025-49557HIGHAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.6%CVE-2021-42703MEDIUMAzeoTech DAQFactoryEPSS 0.6%CVE-2022-45387MEDIUMJenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in aEPSS 0.6%CVE-2021-27911HIGHXSS vulnerability on contacts viewEPSS 0.6%CVE-2018-3764—In Nextcloud Contacts before 2.1.2, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring EPSS 0.6%CVE-2022-0447—Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_typesEPSS 0.6%CVE-2022-43967MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multilingual report due to EPSS 0.6%CVE-2026-41472MEDIUMCyberPanel < 2.4.5 Stored XSS via AI Scanner DashboardEPSS 0.6%CVE-2024-43723MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2022-43968MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboard icons due to un-sEPSS 0.6%CVE-2024-43715MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2024-43714MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2024-43724MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2023-4321HIGHCross-site Scripting (XSS) - Stored in cockpit-hq/cockpitEPSS 0.6%CVE-2024-26367MEDIUMCross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* BuEPSS 0.6%