Weaknesses of type CWE-79

28,989 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-8604MEDIUMSourceCodester Online Food Ordering System Create an Account Page index.php cross site scriptingEPSS 0.6%CVE-2024-8174MEDIUMcode-projects Blood Bank System Login Page login.php cross site scriptingEPSS 0.6%CVE-2024-10177MEDIUMBeds24 Online Booking <= 2.0.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via beds24-link ShortcodeEPSS 0.6%CVE-2024-39308MEDIUMRailsAdmin Cross-site Scripting vulnerability in the list viewEPSS 0.6%CVE-2022-38198MEDIUMBUG-000146513 - Reflected XSS vulnerability in ArcGIS ServerEPSS 0.6%CVE-2024-13722MEDIUMCheckmk NagVis Reflected Cross-site ScriptingEPSS 0.6%CVE-2024-1020LOWRebuild proxy-download getStorageFile cross site scriptingEPSS 0.6%CVE-2026-52854HIGHmediawiki/maps: Stored XSS through the overlays parameter in the display_map parser functionEPSS 0.6%CVE-2022-44279MEDIUMGarage Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /garage/php_action/createBrand.php.EPSS 0.6%CVE-2023-37280MEDIUMPimcore admin UI vulnerable to Cross-site Scripting in two factor authentication setup pageEPSS 0.6%CVE-2021-3619LOWRapid7 Velociraptor Notebooks Authenticated Persistent XSSEPSS 0.6%CVE-2026-55087MEDIUMEtherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)EPSS 0.6%CVE-2025-46719MEDIUMOpen WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functionsEPSS 0.6%CVE-2022-32225—A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. EPSS 0.6%CVE-2023-1418LOWSourceCodester Friendly Island Pizza Website and Ordering System POST Parameter cashconfirm.php cross site scriptingEPSS 0.6%CVE-2024-4519LOWCampcodes Complete Web-Based School Management System teacher_salary_details3.php cross site scriptingEPSS 0.6%CVE-2024-0381MEDIUMWP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag'EPSS 0.6%CVE-2023-1106MEDIUMCross-site Scripting (XSS) - Reflected in flatpressblog/flatpressEPSS 0.6%CVE-2024-2020HIGHCalculated Fields Form Professional <= 5.1.56 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-57977HIGHMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.6%