Weaknesses of type CWE-79

28,833 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-45514MEDIUMAn issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoinEPSS 0.6%CVE-2022-43556MEDIUMConcrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field since the result dasEPSS 0.6%CVE-2024-4724MEDIUMCampcodes Legal Case Management System case-type cross site scriptingEPSS 0.6%CVE-2024-4714MEDIUMCampcodes Complete Web-Based School Management System update_subject.php cross site scriptingEPSS 0.6%CVE-2022-3127MEDIUMCross-site Scripting (XSS) - Stored in jgraph/drawioEPSS 0.6%CVE-2023-24687MEDIUMMojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. ThisEPSS 0.6%CVE-2021-24180—Related Posts for WordPress < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.6%CVE-2022-39338LOWStored cross site scripting (XSS) vulnerability via Authorization Endpoint in user_oidcEPSS 0.6%CVE-2021-41563MEDIUMTad Book3 - Stored XSSEPSS 0.6%CVE-2024-38036MEDIUMBUG-000154827 - Reflected XSS in ArcGIS Experience BuilderEPSS 0.6%CVE-2021-24187—SEO Redirection < 6.4 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.6%CVE-2024-31857MEDIUMForminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain uEPSS 0.6%CVE-2024-4725MEDIUMCampcodes Legal Case Management System client_user cross site scriptingEPSS 0.6%CVE-2021-41567MEDIUMTad Uploader - Stored XSSEPSS 0.6%CVE-2025-46349HIGHYesWiki Vulnerable to Unauthenticated Reflected Cross-site ScriptingEPSS 0.6%CVE-2023-4932MEDIUMReflected Cross-Site Scripting in SAS 9.4EPSS 0.6%CVE-2023-2973LOWSourceCodester Students Online Internship Timesheet Syste cross site scriptingEPSS 0.6%CVE-2021-37860LOWMattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary webEPSS 0.6%CVE-2022-0506HIGHCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.6%CVE-2024-43800MEDIUMserve-static affected by template injection that can lead to XSSEPSS 0.6%