Weaknesses of type CWE-79

28,942 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-24182MEDIUMLuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the compoEPSS 0.6%CVE-2021-33848MEDIUMFresenius Kabi Agilia Connect Infusion System cross site scriptingEPSS 0.6%CVE-2022-40704MEDIUMA XSS vulnerability was found in phoromatic_r_add_test_details.php in phoronix-test-suite.EPSS 0.6%CVE-2023-42496CRITICALReflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and LiferayEPSS 0.6%CVE-2023-6440LOWSourceCodester Book Borrower System add-book.php cross site scriptingEPSS 0.6%CVE-2021-24694—Simple Download Monitor < 3.9.11 - Contributor+ Stored Cross-Site Scripting via ShortcodesEPSS 0.6%CVE-2023-24203MEDIUMCross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitaryEPSS 0.6%CVE-2026-84031CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2021-25046—Modern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSSEPSS 0.6%CVE-2022-25784CRITICALUser controllable HTML element attribute (potential XSS)EPSS 0.6%CVE-2023-43458MEDIUMCross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain seEPSS 0.6%CVE-2023-42498CRITICALReflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and LifeEPSS 0.6%CVE-2022-2404MEDIUMWP Popup Builder < 1.2.9 - Reflected Cross-Site ScriptingEPSS 0.6%CVE-2026-3438MEDIUMNexus Repository 3 - Reflected Cross-Site Scripting (XSS) in ?describe PagesEPSS 0.6%CVE-2022-42066MEDIUMOnline Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.EPSS 0.6%CVE-2023-6442LOWPHPGurukul Nipah Virus Testing Management System add-phlebotomist.php cross site scriptingEPSS 0.6%CVE-2024-13853MEDIUMSEO Tools <= 4.0.7 - Reflected XSSEPSS 0.6%CVE-2023-1857LOWSourceCodester Online Computer and Laptop Store cross site scriptingEPSS 0.6%CVE-2022-2020LOWSourceCodester Prison Management System System Name cross site scriptingEPSS 0.6%CVE-2020-11051MEDIUMXSS in Wiki.jsEPSS 0.6%