Weaknesses of type CWE-79

29,079 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2025-1337MEDIUMEastnets PaymentSafe BIC Search cross site scriptingEPSS 0.5%CVE-2023-0419—Shortcode for Font Awesome < 1.4.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2024-36182MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2024-36201MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2023-3691LOWlayui HTML Attribute cross site scriptingEPSS 0.5%CVE-2022-42112MEDIUMA Cross-site scripting (XSS) vulnerability in the Portal Search module's Sort widget in Liferay Portal 7.2.0 through 7.4.3.24, and Liferay DEPSS 0.5%CVE-2023-33942MEDIUMCross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and LiferaEPSS 0.5%CVE-2021-3816—Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creatEPSS 0.5%CVE-2024-0423LOWCodeAstro Online Food Ordering System dishes.php cross site scriptingEPSS 0.5%CVE-2023-6461HIGHCross-site Scripting (XSS) - Reflected in viliusle/minipaintEPSS 0.5%CVE-2025-49745MEDIUMMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 0.5%CVE-2024-9111MEDIUMProduct Designer <= 1.0.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.5%CVE-2021-32859MEDIUMBaremetrics date range picker vulnerable to Cross-site ScriptingEPSS 0.5%CVE-2025-8349MEDIUMCross-Site Scripting (XSS) stored in Tawk Live ChatEPSS 0.5%CVE-2024-29374MEDIUMA Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" URL parameter.EPSS 0.5%CVE-2025-6948HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2019-25156LOWdstar2018 Agency search.php cross site scriptingEPSS 0.5%CVE-2022-42114MEDIUMA Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through 7.4.3.36, and LiferEPSS 0.5%CVE-2023-0018CRITICALCross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Central management console)EPSS 0.5%CVE-2023-33944MEDIUMCross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, anEPSS 0.5%