Weaknesses of type CWE-79

28,857 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-24425—myStickymenu < 2.5.2 - Authenticated Stored XSSEPSS 0.6%CVE-2021-24426—Backup by 10Web <= 1.0.20 - Reflected Cross-Site Scripting (XSS)EPSS 0.6%CVE-2021-32856MEDIUMMicroweber vulnerable to Cross-site ScriptingEPSS 0.6%CVE-2021-4431LOWmsyk FMDataAPI FMDataAPI_Sample.php cross site scriptingEPSS 0.6%CVE-2021-29434MEDIUMImproper validation of URLs ('Cross-site Scripting') in Wagtail rich text fieldsEPSS 0.6%CVE-2021-24419—WP YouTube Lyte < 1.7.16 - Authenticated Stored XSSEPSS 0.6%CVE-2020-3536MEDIUMCisco SD-WAN vManage Cross-Site Scripting VulnerabilityEPSS 0.6%CVE-2021-24418—Smooth Scroll Page Up/Down Buttons <= 1.4 - Authenticated Stored XSS via psb_positioningEPSS 0.6%CVE-2023-43051MEDIUMIBM Cognos Analytics cross-site scriptingEPSS 0.6%CVE-2023-3565MEDIUMCross-site Scripting (XSS) - Generic in nilsteampassnet/teampassEPSS 0.6%CVE-2020-7546—A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power MonitoriEPSS 0.6%CVE-2022-30685MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.6%CVE-2021-36805MEDIUMAkaunting Invoice Footer Persistent XSSEPSS 0.6%CVE-2022-30684MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.6%CVE-2022-35664MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.6%CVE-2022-30686MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.6%CVE-2022-40931MEDIUMdutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS).EPSS 0.6%CVE-2025-8550MEDIUMatjiu pybbs list cross site scriptingEPSS 0.6%CVE-2024-34481MEDIUMdrupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page.EPSS 0.6%CVE-2022-30682MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.6%