Weaknesses of type CWE-79

28,993 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-39272CRITICALA cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially EPSS 0.6%CVE-2025-1987CRITICALStored XSS in Psono-Client via Malicious Vault Entry URLsEPSS 0.6%CVE-2012-10003LOWahmyi RivetTracker cross site scriptingEPSS 0.6%CVE-2022-2695MEDIUMBeaver Builder – WordPress Page Builder <= 2.5.5.2 - Authenticated Stored Cross-Site Scripting via 'caption'EPSS 0.6%CVE-2022-25604MEDIUMWordPress Price Table plugin <= 0.2.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2023-22911MEDIUMAn issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget repEPSS 0.6%CVE-2024-8521MEDIUMWavelog Live QSO qso index cross site scriptingEPSS 0.6%CVE-2022-27656—The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inEPSS 0.6%CVE-2022-38186HIGHThere is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convincEPSS 0.6%CVE-2021-27788HIGHHCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2022-37306MEDIUMOX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.EPSS 0.6%CVE-2026-15091CRITICALMultiple Vulnerabilities in IBM Engineering AI hub.EPSS 0.6%CVE-2026-27099HIGHJenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of EPSS 0.6%CVE-2022-38188HIGHThere is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user tEPSS 0.6%CVE-2022-38073MEDIUMWordPress Awesome Support plugin <= 6.0.7 - Multiple Authenticated Persistent XSS (Additional Interested Parties)EPSS 0.6%CVE-2023-46735MEDIUMSymfony potential Cross-site Scripting in WebhookControllerEPSS 0.6%CVE-2023-37905MEDIUMCross-site Scripting (XSS) in Source Mode of Editor in ckeditor-wordcount-pluginEPSS 0.6%CVE-2023-43509MEDIUMUnauthenticated Endpoint Allows Sending Arbitrary OnGuard NotificationsEPSS 0.6%CVE-2023-45360MEDIUMAn issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenEPSS 0.6%CVE-2024-2720LOWCampcodes Complete Online DJ Booking System aboutus.php cross site scriptingEPSS 0.6%