Weaknesses of type CWE-79

29,056 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2026-4914MEDIUMStored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessiEPSS 0.5%CVE-2023-24744MEDIUMCross Site Scripting (XSS) vulnerability in Rediker Software AdminPlus 6.1.91.00 allows remote attackers to run arbitrary code via the onloaEPSS 0.5%CVE-2024-2907MEDIUMAGCA – Custom Dashboard & Login Page < 7.2.2 - Admin+ Stored XSS via Image URLEPSS 0.5%CVE-2022-45472MEDIUMCAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.EPSS 0.5%CVE-2015-10028LOWss15-this-is-sparta Main Page roomElement.js cross site scriptingEPSS 0.5%CVE-2023-33408MEDIUMMinical 1.0.0 is vulnerable to Cross Site Scripting (XSS). The vulnerability exists due to insufficient input validation in the application'EPSS 0.5%CVE-2022-37307MEDIUMOX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an eEPSS 0.5%CVE-2026-55090MEDIUMEtherpad: Stored XSS in HTML export via unescaped attribute-pool valuesEPSS 0.5%CVE-2021-42083HIGHAuthenticated Stored XSS in OSNEXUS QuantaStor 6.0.0.335EPSS 0.5%CVE-2022-0350MEDIUMCross-site Scripting (XSS) - Stored in vanessa219/vditorEPSS 0.5%CVE-2023-3293HIGHCross-site Scripting (XSS) - Stored in salesagility/suitecrm-coreEPSS 0.5%CVE-2022-0937MEDIUMStored xss in showdoc through file upload in star7th/showdocEPSS 0.5%CVE-2026-17496HIGHNoteGen chat preview XSS via unsanitized AI/skill HTML renderingEPSS 0.5%CVE-2022-0940MEDIUMStored XSS due to Unrestricted File Upload in star7th/showdocEPSS 0.5%CVE-2022-35226—SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it wilEPSS 0.5%CVE-2024-1720MEDIUMUser Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site ScriptingEPSS 0.5%CVE-2024-36997MEDIUMPersistent Cross-site Scripting (XSS) in conf-web/settings REST endpointEPSS 0.5%CVE-2026-54002HIGHKirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`EPSS 0.5%CVE-2026-73422MEDIUMAstro: Reflected XSS via unescaped View Transition animation propertiesEPSS 0.5%CVE-2026-92144HIGHForminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' ParameterEPSS 0.5%