Weaknesses of type CWE-79

29,045 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-31779MEDIUMWekan v6.84 and earlier is vulnerable to Cross Site Scripting (XSS). An attacker with user privilege on kanban board can insert JavaScript cEPSS 0.6%CVE-2023-28669MEDIUMJenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cross-site scripting (EPSS 0.6%CVE-2024-29271MEDIUMReflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obEPSS 0.6%CVE-2023-4433HIGHCross-site Scripting (XSS) - Stored in cockpit-hq/cockpitEPSS 0.6%CVE-2015-6462—Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed EPSS 0.6%CVE-2025-54597HIGHLinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.EPSS 0.6%CVE-2024-4527LOWCampcodes Complete Web-Based School Management System student_payment_details2.php cross site scriptingEPSS 0.6%CVE-2024-4525LOWCampcodes Complete Web-Based School Management System student_payment_details4.php cross site scriptingEPSS 0.6%CVE-2024-4526LOWCampcodes Complete Web-Based School Management System student_payment_details3.php cross site scriptingEPSS 0.6%CVE-2021-24467—Leaflet Map < 3.0.0 - Arbitrary Settings Update via CSRF Leading to Stored XSSEPSS 0.6%CVE-2023-5127MEDIUMWP Font Awesome <= 1.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.6%CVE-2025-50754CRITICALUnisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submittEPSS 0.6%CVE-2023-1481LOWSourceCodester Monitoring of Students Cyber Accounts System POST Parameter cross site scriptingEPSS 0.6%CVE-2022-38527MEDIUMUCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.EPSS 0.6%CVE-2013-10021LOWdd32 Debug Bar Plugin class-debug-bar-queries.php render cross site scriptingEPSS 0.6%CVE-2012-10013LOWKau-Boy Backend Localization Plugin backend_localization.php cross site scriptingEPSS 0.6%CVE-2023-3681LOWCampcodes Retro Cellphone Online Store modal_add_product.php cross site scriptingEPSS 0.6%CVE-2017-20183LOWExternal Media without Import Plugin external-media-without-import.php print_media_new_panel cross site scriptingEPSS 0.6%CVE-2024-37674MEDIUMCross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameterEPSS 0.6%CVE-2015-10098LOWBroken Link Checker Plugin ui_get_action_links cross site scriptingEPSS 0.6%