Weaknesses of type CWE-79

28,983 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-38189MEDIUMThere is a stored cross-site scripting (XSS) vulnerability in ArcGIS API for JavaScript.EPSS 0.6%CVE-2022-27854MEDIUMWordPress Psychological tests & quizzes plugin <= 0.21.19 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2026-64902MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2022-3069MEDIUMWordlift < 3.37.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-47638MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2021-3539MEDIUMEspoCRM Avatar Persistent XSSEPSS 0.6%CVE-2022-2843LOWMotoPress Timetable and Event Schedule Quick Edit admin-ajax.php cross site scriptingEPSS 0.6%CVE-2023-28636MEDIUMGLPI vulnerable to stored Cross-site Scripting in external linksEPSS 0.6%CVE-2023-3790LOWBoom CMS assets-manager add cross site scriptingEPSS 0.6%CVE-2026-84648HIGHIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestaEPSS 0.6%CVE-2026-45467MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2022-27494HIGHCROSS-SITE SCRIPTING CWE-79EPSS 0.6%CVE-2026-48562MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2026-55019MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2016-2139—In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in $file_link in class/KippoInput.class.php.EPSS 0.6%CVE-2026-45479MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2026-55135MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2026-64916MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2021-33710—A vulnerability has been identified in Teamcenter Active Workspace V4 (All versions < V4.3.9), Teamcenter Active Workspace V5.0 (All versionEPSS 0.6%CVE-2026-55020MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%