Weaknesses of type CWE-79

28,988 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-1526LOWEmlog Pro POST Parameter cross site scriptingEPSS 0.6%CVE-2022-3069MEDIUMWordlift < 3.37.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-45468MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2022-27494HIGHCROSS-SITE SCRIPTING CWE-79EPSS 0.6%CVE-2015-10101LOWGoogle Analytics Top Content Widget Plugin class-tgm-plugin-activation.php cross site scriptingEPSS 0.6%CVE-2024-31634MEDIUMCross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbitrary code via the SeEPSS 0.6%CVE-2026-45462MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2026-47640MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2026-55016MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2026-55019MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2022-2843LOWMotoPress Timetable and Event Schedule Quick Edit admin-ajax.php cross site scriptingEPSS 0.6%CVE-2026-64902MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2022-27854MEDIUMWordPress Psychological tests & quizzes plugin <= 0.21.19 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2026-45467MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2026-84648HIGHIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestaEPSS 0.6%CVE-2023-28636MEDIUMGLPI vulnerable to stored Cross-site Scripting in external linksEPSS 0.6%CVE-2023-3788LOWActiveITzone Active Super Shop CMS Manage Details Page cross site scriptingEPSS 0.6%CVE-2022-2574MEDIUMMeks Easy Social Share < 1.2.8 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-47412MEDIUMONLYOFFICE Workspace Search Stored XSSEPSS 0.6%CVE-2024-31156HIGHBIG-IP Configuration utility XSS vulnerabilityEPSS 0.6%