Weaknesses of type CWE-79

29,080 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-4637LOWep3-bs cross site scriptingEPSS 0.5%CVE-2018-25053MEDIUMmoappi Json2html json2html.js cross site scriptingEPSS 0.5%CVE-2022-45728MEDIUMDoctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.EPSS 0.5%CVE-2022-3631MEDIUMOAuth Client by DigitialPixies <= 1.1.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-38356MEDIUMTinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp optionEPSS 0.5%CVE-2026-55665HIGHDOM-based XSS in Grist via unsanitized links, enabling privilege escalationEPSS 0.5%CVE-2024-28092HIGHUBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks viEPSS 0.5%CVE-2026-59232MEDIUMStored Cross-site Scripting in Prospero Flow CRM lead name fieldEPSS 0.5%CVE-2025-5084MEDIUMPost Grid Master <= 3.4.13 - Reflected Cross-Site Scripting via argsArray['read_more_text']EPSS 0.5%CVE-2026-42052MEDIUMbeets is Vulnerable to XSSEPSS 0.5%CVE-2025-2206MEDIUMaitangbao springboot-manager permission cross site scriptingEPSS 0.5%CVE-2022-21938HIGHMetasys MUI Graphics XSSEPSS 0.5%CVE-2026-59833HIGHSiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)EPSS 0.5%CVE-2026-54527CRITICALJupyterLab Git: Stored XSS leading to RCEEPSS 0.5%CVE-2026-63361HIGHLimeSurvey Community Edition 7.0.5 - Reflected XSS in HTML editor popupEPSS 0.5%CVE-2022-39799MEDIUMAn attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflEPSS 0.5%CVE-2023-1917MEDIUMPowerPress <= 10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2026-48094MEDIUMShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content OutputEPSS 0.5%CVE-2022-27853MEDIUMWordPress Contest Gallery plugin <= 13.1.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2024-38357MEDIUMTinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elementsEPSS 0.5%