Weaknesses of type CWE-79

29,035 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-11447MEDIUMCommunity by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App <=7.0.3.0 - Reflected Cross-Site ScriptingEPSS 0.6%CVE-2023-2293LOWSourceCodester Purchase Order Management System cross site scriptingEPSS 0.6%CVE-2023-2153LOWSourceCodester Complaint Management System POST Parameter editable_ajax.php cross site scriptingEPSS 0.6%CVE-2026-30235MEDIUMBusiness Logic Error on OpenProject through hyperlinks in markdown using DOM clobberingEPSS 0.6%CVE-2023-1200LOWehuacui bbs cross site scriptingEPSS 0.6%CVE-2026-11913CRITICALMother May I - Critical - Unsupported - SA-CONTRIB-2026-045EPSS 0.6%CVE-2022-46287MEDIUMCross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to inject an arEPSS 0.6%CVE-2025-66918HIGHedoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.EPSS 0.6%CVE-2022-3765HIGHCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.6%CVE-2024-23905MEDIUMJenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generateEPSS 0.6%CVE-2023-2708MEDIUMVideo Gallery <= 1.0.10 - Reflected Cross-Site ScriptingEPSS 0.6%CVE-2022-42117MEDIUMA Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and Liferay DXP 7.3 beforEPSS 0.6%CVE-2023-2349LOWSourceCodester Service Provider Management System index.php cross site scriptingEPSS 0.6%CVE-2023-2425LOWSourceCodester Simple Student Information System Add New Course cross site scriptingEPSS 0.6%CVE-2023-2350LOWSourceCodester Service Provider Management System Users.php cross site scriptingEPSS 0.6%CVE-2023-3970LOWGZ Scripts Availability Booking Calendar PHP Image cross site scriptingEPSS 0.6%CVE-2023-3035LOWGuangdong Pythagorean OA Office System Schedule cross site scriptingEPSS 0.6%CVE-2023-3058LOW07FLY CRM User Profile cross site scriptingEPSS 0.6%CVE-2026-58191MEDIUMAppium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routesEPSS 0.6%CVE-2022-3561MEDIUMCross-site Scripting (XSS) - Generic in librenms/librenmsEPSS 0.6%