Weaknesses of type CWE-79

29,035 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2026-68534LOWConcrete CMS below 9.5.2 is vulnerable to Stored XSS via unescaped Express entry labels in association selectorsEPSS 0.6%CVE-2022-36432MEDIUMThe Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-siteEPSS 0.6%CVE-2022-25618LOWWordPress wpDataTables plugin <= 2.1.27 - Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2021-41836MEDIUMFathom Analytics <= 3.0.4 Authenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-36405MEDIUMWordPress amCharts: Charts and Maps plugin <= 1.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2020-20521MEDIUMCross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter.EPSS 0.6%CVE-2020-21268MEDIUMCross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameEPSS 0.6%CVE-2026-66395CRITICALSiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan ProtocolEPSS 0.6%CVE-2021-36919MEDIUMWordPress Awesome Support plugin <= 6.0.6 - Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.6%CVE-2023-5688CRITICALCross-site Scripting (XSS) - DOM in modoboa/modoboaEPSS 0.6%CVE-2022-37421MEDIUMSilverstripe silverstripe/cms through 4.11.0 allows XSS.EPSS 0.6%CVE-2022-38146MEDIUMSilverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).EPSS 0.6%CVE-2024-28165HIGHCross site scripting vulnerability in SAP BusinessObjects Business Intelligence PlatformEPSS 0.6%CVE-2024-10461MEDIUMIn multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a downlEPSS 0.6%CVE-2026-32119MEDIUMOpenEMR has Stored DOM XSS via SearchHighlight text-node reconstruction on Custom Report pageEPSS 0.6%CVE-2024-0776LOWLinZhaoguan pb-cms Comment cross site scriptingEPSS 0.6%CVE-2023-49453MEDIUMReflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obEPSS 0.6%CVE-2024-23905MEDIUMJenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generateEPSS 0.6%CVE-2023-1200LOWehuacui bbs cross site scriptingEPSS 0.6%CVE-2025-66918HIGHedoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.EPSS 0.6%