Weaknesses of type CWE-79

28,949 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2025-30223CRITICALBeego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User InputEPSS 0.6%CVE-2021-21442MEDIUMXSS vulnerability in Time AccountingEPSS 0.6%CVE-2024-2081MEDIUMFooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-29105MEDIUMThere is a stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below.EPSS 0.6%CVE-2023-2298HIGHOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-42486MEDIUMStored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attackeEPSS 0.6%CVE-2026-49995MEDIUMTautulli: Stored Cross-Site Scripting (XSS) in the newsletterEPSS 0.6%CVE-2022-46087MEDIUMCloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notificatEPSS 0.6%CVE-2024-8017CRITICALCross-site Scripting (XSS) in open-webui/open-webuiEPSS 0.6%CVE-2022-1840LOWHome Clean Services Management System cross site scriptingEPSS 0.6%CVE-2024-0826MEDIUMQi Addons For Elementor <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-25763MEDIUMJenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored crEPSS 0.6%CVE-2024-4036MEDIUMSydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-15401HIGHVikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' ParameterEPSS 0.6%CVE-2024-4156MEDIUMEssential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-25986MEDIUMDjango-wiki - Stored Cross-Site Scripting (XSS) in Notifications SectionEPSS 0.6%CVE-2024-11370MEDIUMSubaccounts for WooCommerce <= 1.6.0 - Reflected Cross-Site ScriptingEPSS 0.6%CVE-2022-0209MEDIUMMitsol Social Post Feed < 1.11 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-34605HIGHSiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )EPSS 0.6%CVE-2023-25764MEDIUMJenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generatedEPSS 0.6%