Weaknesses of type CWE-79

28,935 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-40191CRITICALReflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and LiEPSS 0.6%CVE-2021-24691—Quiz And Survey Master < 7.3.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-24464—YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSSEPSS 0.6%CVE-2023-38491MEDIUMKirby vulnerable to Cross-site scripting (XSS) from MIME type auto-detection of uploaded filesEPSS 0.6%CVE-2023-29025MEDIUMRockwell Automation ArmorStart ST Vulnerable to Cross-Site Scripting AttackEPSS 0.6%CVE-2023-1240HIGHCross-site Scripting (XSS) - Stored in answerdev/answerEPSS 0.6%CVE-2021-24654—User Registration < 2.0.2 - Low Privilege Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-24593—Business Hours Indicator < 2.3.5 - Authenticated Stored XSSEPSS 0.6%CVE-2023-45818MEDIUMCross-site Scripting vulnerability in TinyMCE undo/redo, getContent API, resetContent API, and Autosave pluginEPSS 0.6%CVE-2021-24523—Daily Prayer Time < 2021.08.10 - Authenticated Stored XSSEPSS 0.6%CVE-2021-24302—Hana Flv Player <= 3.1.3 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.6%CVE-2021-24505—Forms < 1.12.3 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.6%CVE-2021-24439—Browser Screenshots < 1.7.6 - Contributor+ Stored XSSEPSS 0.6%CVE-2021-24277—RSS for Yandex Turbo < 1.30 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.6%CVE-2021-24367—WP Config File Editor <= 1.7.1 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.6%CVE-2024-30921MEDIUMCross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the photo.php componentEPSS 0.6%CVE-2021-24232—Advanced Booking Calendar < 1.6.8 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.6%CVE-2023-3020CRITICALCross-site Scripting (XSS) - Reflected in mkucej/i-librarian-freeEPSS 0.6%CVE-2021-24577—Coming Soon and Maintenance Mode < 3.5.3 - Authenticated Stored XSSEPSS 0.6%CVE-2022-3391MEDIUMRetain Live Chat <= 0.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%