Weaknesses of type CWE-79

28,832 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-0606CRITICALCross-site Scripting (XSS) - Reflected in ampache/ampacheEPSS 0.6%CVE-2022-2015MEDIUMCross-site Scripting (XSS) - Stored in jgraph/drawioEPSS 0.6%CVE-2022-40289CRITICALStored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via file upload and download functionality.EPSS 0.6%CVE-2021-1374MEDIUMCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family Stored Cross-Site Scripting VulnerabilityEPSS 0.6%CVE-2022-1755MEDIUMSVG Support < 2.5 - Author+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-2098LOWSourceCodester Vehicle Service Management System topBarNav.php cross site scriptingEPSS 0.6%CVE-2023-2100LOWSourceCodester Vehicle Service Management System index.php cross site scriptingEPSS 0.6%CVE-2020-5266MEDIUMStored XSS on back office edit pageEPSS 0.6%CVE-2026-54393MEDIUMMISP Overmind theme stored XSS via unvalidated homepage settingEPSS 0.6%CVE-2023-27131MEDIUMCross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Post Editorparameter.EPSS 0.6%CVE-2015-10013LOWWebDevStudios taxonomy-switcher Plugin taxonomy-switcher.php taxonomy_switcher_init cross site scriptingEPSS 0.6%CVE-2021-24516—PlanSo Forms <= 2.6.3 - Authenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2017-20177LOWWangGuard Plugin WGG User List wangguard-user-info.php wangguard_users_info cross site scriptingEPSS 0.6%CVE-2023-24769MEDIUMChangedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulneEPSS 0.6%CVE-2022-48325MEDIUMMultiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects the following parametEPSS 0.6%CVE-2021-25048—KingComposer <= 2.9.6 - Subscriber+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-6945LOWSourceCodester Online Student Management System edit-student-detail.php cross site scriptingEPSS 0.6%CVE-2023-36806MEDIUMContao cross site scripting vulnerability via input unit widgetEPSS 0.6%CVE-2025-55303MEDIUMUnauthorized third-party images in Astro’s _image endpointEPSS 0.6%CVE-2024-56519HIGHAn issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.EPSS 0.6%