Weaknesses of type CWE-79

28,993 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-11986CRITICALStored XSS in CrushFTPEPSS 0.6%CVE-2024-9107MEDIUMStored XSS in gaizhenbiao/chuanhuchatgptEPSS 0.6%CVE-2023-3821MEDIUMCross-site Scripting (XSS) - Stored in pimcore/pimcoreEPSS 0.6%CVE-2021-36832MEDIUMWordPress Icegram plugin <= 2.0.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2026-34693HIGHAdobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)EPSS 0.6%CVE-2021-36884MEDIUMWordPress Backup Migration plugin <= 1.1.5 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2023-3784LOWDooblou WiFi File Explorer cross site scriptingEPSS 0.6%CVE-2023-2824LOWSourceCodester Dental Clinic Appointment Reservation System POST Parameter service.php cross site scriptingEPSS 0.6%CVE-2024-3045HIGHPDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-45797MEDIUMHeyForm Vulnerable to Stored XSS via Unauthenticated SVG File UploadEPSS 0.6%CVE-2023-45050MEDIUMWordPress Jetpack Plugin <= 12.8-a.1 is vulnerable to Cross Site Scripting (XSS)EPSS 0.6%CVE-2022-41993MEDIUMCross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arEPSS 0.6%CVE-2024-39272CRITICALA cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially EPSS 0.6%CVE-2017-20182LOWMobile Vikings Django AJAX Utilities Backslash pagination.js Pagination cross site scriptingEPSS 0.6%CVE-2023-3946MEDIUM A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 SP1 Update 1allows a remote unauthenticated attacker to potentialEPSS 0.6%CVE-2025-1987CRITICALStored XSS in Psono-Client via Malicious Vault Entry URLsEPSS 0.6%CVE-2022-41139MEDIUMMITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execution of arbitrary comEPSS 0.6%CVE-2024-0652LOWPHPGurukul Company Visitor Management System search-visitor.php cross site scriptingEPSS 0.6%CVE-2023-3070HIGHCross-site Scripting (XSS) - Stored in tsolucio/corebosEPSS 0.6%CVE-2023-22454HIGHDiscourse vulnerable to Cross-site Scripting through pending post titles descriptionsEPSS 0.6%