Weaknesses of type CWE-79

28,384 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2018-5405The Quest Kace K1000 Appliance is vulnerable to JavaScript injection.EPSS 3.7%CVE-2021-24387Real Estate 7 < 3.1.1 - Reflected Cross-Site Scripting (XSS)EPSS 3.7%CVE-2025-34178MEDIUMNetgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site ScriptingEPSS 3.7%CVE-2026-3228MEDIUMNextScripts: Social Networks Auto-Poster <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'nxs_fbembed' ShortcodeEPSS 3.7%CVE-2025-69231HIGHOpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege EscalationEPSS 3.6%CVE-2025-20303MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker EPSS 3.6%CVE-2022-0901Ad Inserter < 2.7.12 - Reflected Cross-Site ScriptingEPSS 3.6%CVE-2024-28090MEDIUMTechnicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proximity to conduct storEPSS 3.6%CVE-2021-24498Calendar Event Multi View < 1.4.01 - Unauthenticated Reflected Cross-Site Scripting (XSS)EPSS 3.5%CVE-2022-1163MEDIUMCross-site Scripting (XSS) - Stored in mineweb/minewebcmsEPSS 3.5%CVE-2021-24298Simple Giveaways < 2.36.2 - Unauthenticated Reflected Cross-Site Scripting (XSS)EPSS 3.5%CVE-2021-22872Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivEPSS 3.4%CVE-2018-6341MEDIUMReact applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That EPSS 3.4%CVE-2024-33113MEDIUMD-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.EPSS 3.4%CVE-2022-0201Permalink Manager < 2.2.15 - Reflected Cross-Site ScriptingEPSS 3.4%CVE-2021-24495Marmoset Viewer < 1.9.3 - Reflected Cross Site ScriptingEPSS 3.3%CVE-2021-21043MEDIUMReflected Cross-site Scripting (XSS) on version-compare and page-compare toolsEPSS 3.3%CVE-2023-2822MEDIUMEllucian Ethos Identity logout cross site scriptingEPSS 3.3%CVE-2021-37859HIGHReflected XSS in OAuth FlowEPSS 3.3%CVE-2022-0967MEDIUMStored XSS via File Upload in star7th/showdoc in star7th/showdoc in star7th/showdocEPSS 3.3%