Weaknesses of type CWE-79

29,079 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-1535HIGHCross-site Scripting (XSS) - Stored in answerdev/answerEPSS 0.5%CVE-2022-45016MEDIUMA cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scriptEPSS 0.5%CVE-2016-15025LOWgenerator-hottowel 404 Error _app.js cross site scriptingEPSS 0.5%CVE-2022-45013MEDIUMA cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web sEPSS 0.5%CVE-2023-1090MEDIUMWP SMTP Mailing Queue < 2.0.1 - Admin+ Stored XSSEPSS 0.5%CVE-2021-37208CRITICALA vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC,EPSS 0.5%CVE-2022-25609MEDIUMWordPress Yoo Slider plugin <= 2.0.0 - Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2021-36828MEDIUMWordPress WP Maintenance plugin <= 6.0.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2024-3588MEDIUMGetwid – Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Countdown'EPSS 0.5%CVE-2022-45012MEDIUMA cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts orEPSS 0.5%CVE-2022-4588LOWBoston Sleep slice Layout cross site scriptingEPSS 0.5%CVE-2022-45014MEDIUMA cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scriptEPSS 0.5%CVE-2022-45543MEDIUMCross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, title, tpp, or usernamEPSS 0.5%CVE-2022-45015MEDIUMA cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scriptEPSS 0.5%CVE-2015-10072LOWNREL api-umbrella-web Flash Message cross site scriptingEPSS 0.5%CVE-2022-27505—Reflected cross site scripting (XSS)EPSS 0.5%CVE-2023-30454MEDIUMAn issue was discovered in ebankIT before 7. Document Object Model based XSS exists within the /Security/Transactions/Transactions.aspx endpEPSS 0.5%CVE-2022-4877LOWsnoyberg keter Proxy.hs cross site scriptingEPSS 0.5%CVE-2024-25865MEDIUMCross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia seEPSS 0.5%CVE-2022-4699MEDIUMMediaElement.js – HTML5 Video & Audio Player <= 4.2.8 - Contributor+ Stored XSS via ShortcodeEPSS 0.5%