Weaknesses of type CWE-79

29,057 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-39025MEDIUMe-Excellence Inc. U-Office Force - Reflected XSSEPSS 0.5%CVE-2022-29442MEDIUMPrivate Messages For WordPress <= 2.1.10 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2023-4841MEDIUMFeeds for YouTube <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2020-15119MEDIUMDOM-based XSS in auth0-lockEPSS 0.5%CVE-2014-125096LOWFancy Gallery Plugin Options Page class.options.php cross site scriptingEPSS 0.5%CVE-2014-125095LOWBestWebSoft Contact Form Plugin bws_menu.php bws_add_menu_render cross site scriptingEPSS 0.5%CVE-2022-2729MEDIUMCross-site Scripting (XSS) - DOM in openemr/openemrEPSS 0.5%CVE-2022-29440MEDIUMWordPress Promotion Slider plugin <= 3.3.4 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.5%CVE-2026-81753MEDIUMFlowintel Stored XSS in Case Notes via Malicious Mermaid Diagram ContentEPSS 0.5%CVE-2023-0310CRITICALCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.5%CVE-2025-25460MEDIUMA stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allowEPSS 0.5%CVE-2023-2477LOWFunadmin Cx.php tagLoad cross site scriptingEPSS 0.5%CVE-2024-2293MEDIUMSite Reviews <= 6.11.4 - Authenticated(Subscriber+) Stored Cross-Site Scripting via display nameEPSS 0.5%CVE-2026-0534HIGHStored XSS in the value of a part attributeEPSS 0.5%CVE-2024-1919LOWSourceCodester Online Job Portal Manage Walkin Page ManageWalkin.php cross site scriptingEPSS 0.5%CVE-2022-36390MEDIUMWordPress Event Calendar – Calendar plugin <= 1.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2013-10028LOWEELV Newsletter Plugin lettreinfo.php style_newsletter cross site scriptingEPSS 0.5%CVE-2022-39024MEDIUMe-Excellence Inc. U-Office Force - Reflected XSSEPSS 0.5%CVE-2023-6923MEDIUMMatomo <= 4.15.3 - Reflected Cross-Site Scripting via idsiteEPSS 0.5%CVE-2024-11435MEDIUMsalavat counter Plugin <= 0.9.4 - Reflected Cross-Site ScriptingEPSS 0.5%