Weaknesses of type CWE-79

28,988 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2026-54505LOWTREK: Stored cross-user HTML injection via trip title in the Journey suggestion bannerEPSS 0.6%CVE-2026-54606HIGHSunEditor: DOM XSS in SunEditor Embed Plugin via External Script Element After Iframe EmbedEPSS 0.6%CVE-2020-36194MEDIUMXSS Vulnerability in QTS and QuTS heroCommand Injection Vulnerabilities in QTS and QuTS heroEPSS 0.6%CVE-2024-0438MEDIUMHappy Addons for Elementor <= 3.10.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-24416—StreamCast < 2.1.1 - Contributor+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-44657HIGHMantisBT: Stored XSS in File DownloadEPSS 0.6%CVE-2021-23027—On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, and 14.1.x before 14.1.4.3, a DOM based cross-site scripting (XSS) vulnerability EPSS 0.6%CVE-2021-24415—Polo Video Gallery <= 1.2 - Contributor+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-44201—Cross-site scripting (XSS) was possible in notification pop-upsEPSS 0.6%CVE-2024-3426LOWSourceCodester Online Courseware editt.php cross site scriptingEPSS 0.6%CVE-2022-38376MEDIUMMultiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC EPSS 0.6%CVE-2021-21004HIGHCross-site Scripting Vulnerability in Phoenix Contact FL SWITCH SMCS series productsEPSS 0.6%CVE-2025-47977HIGHNuance Digital Engagement Platform Spoofing VulnerabilityEPSS 0.6%CVE-2021-23054—On version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a reflected croEPSS 0.6%CVE-2024-13219MEDIUMPolicy Genius <= 2.0.4 - Reflected XSSEPSS 0.6%CVE-2025-66481CRITICALDeepChat's Incomplete XSS Fix Allows RCE through Mermaid ContentEPSS 0.6%CVE-2025-22465MEDIUMReflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execEPSS 0.6%CVE-2026-13424HIGHOnline Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX actionEPSS 0.6%CVE-2022-20629MEDIUMCisco Firepower Management Center Software Cross-Site Scripting VulnerabilitiesEPSS 0.6%CVE-2022-20781MEDIUMCisco Web Security Appliance Stored Cross-Site Scripting VulnerabilityEPSS 0.6%