Weaknesses of type CWE-79

28,947 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-30003MEDIUMSourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then creEPSS 0.6%CVE-2022-39054MEDIUMCOWELL INFORMATION SYSTEM CO., LTD. enterprise travel management system - Reflected XSSEPSS 0.6%CVE-2022-39035MEDIUMSmart eVision - Stored XSSEPSS 0.6%CVE-2022-4029MEDIUMSimple:Press <= 6.8 - Reflected Cross-Site Scripting via Cookie ValueEPSS 0.6%CVE-2026-12496HIGHLoytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA serverEPSS 0.6%CVE-2024-34707HIGHNautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pagesEPSS 0.6%CVE-2024-50346MEDIUMWebFeed HTML injection vulnerabilitiesEPSS 0.6%CVE-2026-45738HIGHArgo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalationEPSS 0.6%CVE-2018-16484—A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escEPSS 0.6%CVE-2026-55730HIGHLoytec LWEB802: Reflected Cross-Site Scripting in LWEB802EPSS 0.6%CVE-2022-39053MEDIUMHEIMAVISTA INC. Rpage - Reflected XSSEPSS 0.6%CVE-2023-48986MEDIUMCross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attackerEPSS 0.6%CVE-2024-3695LOWSourceCodester Computer Laboratory Management System Users.php cross site scriptingEPSS 0.6%CVE-2017-20153LOWaerouk imageserve cross site scriptingEPSS 0.6%CVE-2023-3158HIGHMail Control <= 0.2.8 - Unauthenticated Stored Cross-Site Scripting via Email SubjectEPSS 0.6%CVE-2023-3783LOWWebile HTTP POST Request cross site scriptingEPSS 0.6%CVE-2023-2388LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-28639MEDIUMGLPI vulnerable to reflected Cross-site Scripting in search pagesEPSS 0.6%CVE-2023-6303LOWCSZCMS Site Settings Page cross site scriptingEPSS 0.6%CVE-2023-2387LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%