Weaknesses of type CWE-79

28,832 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-56519HIGHAn issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.EPSS 0.6%CVE-2023-6945LOWSourceCodester Online Student Management System edit-student-detail.php cross site scriptingEPSS 0.6%CVE-2026-27616HIGHVikunja Vulnerable to Stored Cross-Site Scripting (XSS) via Unsanitized SVG Attachment Upload Leading to Token ExposureEPSS 0.6%CVE-2023-25841MEDIUMBUG-000158075 Stored XSS issue in ArcGIS ServerEPSS 0.6%CVE-2022-30678MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.6%CVE-2022-30681MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.6%CVE-2025-3929MEDIUMStored XSS vulnerability in MDaemon Email ServerEPSS 0.6%CVE-2021-38674MEDIUMReflected XSS Vulnerability in TFTPEPSS 0.6%CVE-2023-39208MEDIUMImproper input validation in Zoom Desktop Client for Linux before version 5.15.10 may allow an unauthenticated user to conduct a denial of sEPSS 0.6%CVE-2022-3339MEDIUMReflected XSS in Trellix ePO serverEPSS 0.6%CVE-2024-45812MEDIUMDOM Clobbering gadget found in vite bundled scripts that leads to XSS in ViteEPSS 0.6%CVE-2025-64538CRITICALAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2023-3144LOWSourceCodester Online Discussion Forum Site manage_post.php cross site scriptingEPSS 0.6%CVE-2024-3715HIGHDatabase for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-2691LOWSourceCodester Personnel Property Equipment System POST Parameter add_item.php cross site scriptingEPSS 0.6%CVE-2021-33852—A cross-site scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user's browser and can use an application as the vehicEPSS 0.6%CVE-2022-30680MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.6%CVE-2022-28707HIGHOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, a stored cross-sitEPSS 0.6%CVE-2023-5302LOWSourceCodester Best Courier Management System Manage Account Page cross site scriptingEPSS 0.6%CVE-2021-24292—Happy Addons for Elementor Free < 2.24.0 and Pro < 1.17.0 - Contributor+ Stored XSSEPSS 0.6%