Weaknesses of type CWE-79

28,973 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-27592MEDIUMStored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handlerEPSS 0.6%CVE-2014-125103LOWBestWebSoft Twitter Plugin twitter.php twttr_settings_page cross site scriptingEPSS 0.6%CVE-2021-42329MEDIUMShinHer Information Co., LTD. ShinHer StudyOnline System - Stored XSSEPSS 0.6%CVE-2021-30170MEDIUMJun-He Technology Ltd. ERP POS - Stored XSS-1EPSS 0.6%CVE-2024-34355LOWTYPO3 vulnerable to an HTML Injection in the History ModuleEPSS 0.6%CVE-2021-33231MEDIUMCross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbiEPSS 0.6%CVE-2021-30172MEDIUMJun-He Technology Ltd. Quan-Fang-Wei-Tong-Xun system - Reflected XSSEPSS 0.6%CVE-2023-32977MEDIUMJenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a storedEPSS 0.6%CVE-2021-42335MEDIUMHuachu Digital Technology Co.,Ltd. Easytest - Stored XSSEPSS 0.6%CVE-2021-32539MEDIUMHundred Plus 101EIP - Stored XSS-1EPSS 0.6%CVE-2021-32544MEDIUMIntelligent global technology Ltd, igt+ - DOM-based Cross-Site ScriptingEPSS 0.6%CVE-2021-30171MEDIUMJun-He Technology Ltd. ERP POS - Stored XSS-2EPSS 0.6%CVE-2021-3834MEDIUMIntegria IMS vulnerable to Cross Site Scripting (XSS)EPSS 0.6%CVE-2023-25292MEDIUMReflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain seEPSS 0.6%CVE-2022-1028—WordPress Security < 4.2.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-1995—miniOrange's Malware Scanner < 4.5.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2025-25427HIGHXSS in TP-Link TL-WR841N v14/v14.6/v14.8 Upnp pageEPSS 0.6%CVE-2023-4707LOWInfosoftbd Clcknshop all cross site scriptingEPSS 0.6%CVE-2021-36870MEDIUMWordPress WP Google Maps plugin <= 8.1.12 - Multiple Authenticated Persistent XSS vulnerabilitiesEPSS 0.6%CVE-2023-0829HIGHCross-Site Scripting (XSS) vulnerability in PleskEPSS 0.6%