Weaknesses of type CWE-79

29,050 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2019-18574MEDIUMRSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the Security Console. A EPSS 0.6%CVE-2025-25190MEDIUM[XBOW-025-033] Cross-Site Scripting (XSS) via EchoProcess Service in ZOO-Project WPS ServerEPSS 0.6%CVE-2023-0794HIGHCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.6%CVE-2024-25152CRITICALStored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versionEPSS 0.6%CVE-2024-25603CRITICALStored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and olEPSS 0.6%CVE-2023-0791HIGHCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.6%CVE-2015-10010LOWOpenDNS OpenResolve API endpoints.py get cross site scriptingEPSS 0.6%CVE-2026-35035HIGHCI4MS Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSSEPSS 0.6%CVE-2023-4520MEDIUMFV Flowplayer Video Player <= 7.5.37.7212 - Insufficient Input Validation to Unauthenticated Stored Cross-Site Scripting and Arbitrary Usermeta UpdateEPSS 0.6%CVE-2022-37328LOWWordPress History Timeline plugin <= 1.0.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2026-21451MEDIUMBagisto has HTML Filter Bypass that Enables Stored XSSEPSS 0.6%CVE-2023-42478HIGHCross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence PlatformEPSS 0.6%CVE-2023-6033HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.6%CVE-2024-0384MEDIUMWP Recipe Maker <= 9.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Recipe NotesEPSS 0.6%CVE-2023-1275LOWSourceCodester Phone Shop Sales Managements System CAPTCHA index.php cross site scriptingEPSS 0.6%CVE-2024-3068MEDIUMCustom Field Suite <= 2.6.5 - Authenticated (Admin+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2024-12790MEDIUMcode-projects Hostel Management Site room-details.php cross site scriptingEPSS 0.6%CVE-2023-1948LOWPHPGurukul BP Monitoring Management System Add New Family Member add-family-member.php cross site scriptingEPSS 0.6%CVE-2024-27752MEDIUMCross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in thEPSS 0.6%CVE-2021-26263HIGHCross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15.0, allows remote atEPSS 0.6%