Weaknesses of type CWE-79

29,072 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-29418MEDIUMWordPress Night Mode plugin <= 1.0.0 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2023-23354HIGHQuLog CenterEPSS 0.5%CVE-2023-5658MEDIUMWP MapIt <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2022-4735LOWasrashley dash-live DOM Node media.js ready cross site scriptingEPSS 0.5%CVE-2024-1425MEDIUMEmbedPress <= 3.9.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Google Calendar Widget LinkEPSS 0.5%CVE-2020-11065MEDIUMCross-Site Scripting in TYPO3 CMSEPSS 0.5%CVE-2025-25973MEDIUMA stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute aEPSS 0.5%CVE-2023-5667MEDIUMTab Ultimate <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2020-11064MEDIUMCross-Site Scripting in TYPO3 CMSEPSS 0.5%CVE-2020-11070MEDIUMCross-Site Scripting in SVG SanitizerEPSS 0.5%CVE-2026-49279HIGHWWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)EPSS 0.5%CVE-2021-36686MEDIUMCross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page.EPSS 0.5%CVE-2023-5743MEDIUMTelephone Number Linker <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2026-25786CRITICALAffected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interfaceEPSS 0.5%CVE-2022-28354MEDIUMIn the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.EPSS 0.5%CVE-2026-25787CRITICALAffected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the EPSS 0.5%CVE-2022-29438MEDIUMWordPress Image Slider by NextCode plugin <= 1.1.2 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2019-25094LOWinnologi appointments Extension Appointment cross site scriptingEPSS 0.5%CVE-2023-5469MEDIUMDrop Shadow Boxes <= 1.7.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2022-29476MEDIUMWordPress Notification Bar for WordPress plugin <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%