Weaknesses of type CWE-79

28,965 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-36857MEDIUMWordPress Testimonial Builder plugin <= 1.6.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2024-3675MEDIUMRoyal Elementor Addons and Templates <= 1.3.971 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget AttributesEPSS 0.6%CVE-2021-4038MEDIUMNSM vulnerable to XSSEPSS 0.6%CVE-2023-4919MEDIUMiframe <= 4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'iframe' ShortcodeEPSS 0.6%CVE-2015-10107LOWSimplr Registration Form Plus+ Plugin cross site scriptingEPSS 0.6%CVE-2014-125090LOWMedia Downloader Plugin getfile.php dl_file_resumable cross site scriptingEPSS 0.6%CVE-2026-44203HIGHOpenAM: Pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)EPSS 0.6%CVE-2023-29205CRITICALorg.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macroEPSS 0.6%CVE-2022-34475MEDIUMSVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitEPSS 0.6%CVE-2026-44793HIGHOpenAM: Pre-authentication Reflected XSS in SAML2 Cluster Cookie-Hash-Redirect Path via `FSUtils.postToTarget`EPSS 0.6%CVE-2022-1085LOWCLTPHP POST Parameter cross site scriptingEPSS 0.6%CVE-2024-2030MEDIUMDatabase for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcodeEPSS 0.6%CVE-2022-45020HIGHRukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /rukovoditel/index.php?moEPSS 0.6%CVE-2022-4902LOWeXo Chat Application Mention ExoChatMessageComposer.vue cross site scriptingEPSS 0.6%CVE-2020-19699MEDIUMCross Site Scripting vulnerability found in KOHGYLW Kiftd v.1.0.18 allows a remote attacker to execute arbitrary code via the <ifram> tag inEPSS 0.6%CVE-2021-3904MEDIUMCross-site Scripting (XSS) - Stored in getgrav/gravEPSS 0.6%CVE-2022-2731MEDIUMCross-site Scripting (XSS) - Reflected in openemr/openemrEPSS 0.6%CVE-2023-5273LOWSourceCodester Best Courier Management System manage_parcel_status.php cross site scriptingEPSS 0.6%CVE-2023-1799LOWEyouCMS login.php cross site scriptingEPSS 0.6%CVE-2023-1179LOWSourceCodester Computer Parts Sales and Inventory System Add Supplier cross site scriptingEPSS 0.6%