Weaknesses of type CWE-79

29,046 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-1481LOWSourceCodester Monitoring of Students Cyber Accounts System POST Parameter cross site scriptingEPSS 0.6%CVE-2015-10092LOWQtranslate Slug Plugin class-qtranslate-slug.php add_slug_meta_box cross site scriptingEPSS 0.6%CVE-2012-10007LOWmadgicweb BuddyStream Plugin ShareBox.php cross site scriptingEPSS 0.6%CVE-2026-24128MEDIUMXWiki Affected by Reflected Cross-Site Scripting (XSS) in Error MessagesEPSS 0.6%CVE-2023-3681LOWCampcodes Retro Cellphone Online Store modal_add_product.php cross site scriptingEPSS 0.6%CVE-2012-10014LOWKau-Boy Backend Localization Plugin backend_localization.php localize_backend cross site scriptingEPSS 0.6%CVE-2025-51488MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to store and execute arbitEPSS 0.6%CVE-2024-37674MEDIUMCross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameterEPSS 0.6%CVE-2023-6613LOWTypecho Logo options-theme.php cross site scriptingEPSS 0.6%CVE-2024-9148CRITICALFlowise Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-2428MEDIUMCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.6%CVE-2022-37328LOWWordPress History Timeline plugin <= 1.0.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2024-26266CRITICALMultiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and LifEPSS 0.6%CVE-2022-2579LOWSourceCodester Garage Management System createUser.php cross site scriptingEPSS 0.6%CVE-2023-40013HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in external-svg-loaderEPSS 0.6%CVE-2023-4520MEDIUMFV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta UpdateEPSS 0.6%CVE-2019-18574MEDIUMRSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A EPSS 0.6%CVE-2024-4334MEDIUMSupreme Modules Lite – Divi Theme, Extra Theme and Divi Builder <= 2.5.3 - Authenticated (Contributor+) DOM-Based Cross-Site ScriptingEPSS 0.6%CVE-2021-23854HIGHReflected XSS in page parameterEPSS 0.6%CVE-2024-25601CRITICALStored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and oldEPSS 0.6%