Weaknesses of type CWE-79

29,080 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-28092HIGHUBEE DDW365 XCNDDW365 8.14.3105 software on hardware 3.13.1 allows a remote attacker within Wi-Fi proximity to conduct stored XSS attacks viEPSS 0.5%CVE-2025-2207MEDIUMaitangbao springboot-manager dept cross site scriptingEPSS 0.5%CVE-2026-59833HIGHSiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)EPSS 0.5%CVE-2023-3500MEDIUMImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2023-1917MEDIUMPowerPress <= 10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2023-0878MEDIUMCross-site Scripting (XSS) - Generic in nuxt/frameworkEPSS 0.5%CVE-2022-41206MEDIUMSAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated attacker to send user-coEPSS 0.5%CVE-2022-43271MEDIUMInhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerability via the User profEPSS 0.5%CVE-2023-33940MEDIUMCross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before updEPSS 0.5%CVE-2024-32344MEDIUMA cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML EPSS 0.5%CVE-2023-20060MEDIUMCisco Prime Collaboration Deployment Cross-Site Scripting VulnerabilityEPSS 0.5%CVE-2023-5707MEDIUMSEO Slider <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2024-24512MEDIUMCross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.EPSS 0.5%CVE-2025-3554MEDIUMphpshe api.php cross site scriptingEPSS 0.5%CVE-2024-41808HIGHOpenObserve stored XSS vulnerability may lead to complete account takeoverEPSS 0.5%CVE-2023-41703MEDIUMUser ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when workEPSS 0.5%CVE-2021-39036MEDIUMIBM Cognos Analytics cross-site scriptingEPSS 0.5%CVE-2023-5917LOWphpBB Smiley Pack acp_icons.php main cross site scriptingEPSS 0.5%CVE-2024-1794HIGHForminator <= 1.29.0 - Unauthenticated Stored Cross-Site Scripting via File UploadEPSS 0.5%CVE-2023-41704HIGHProcessing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script cEPSS 0.5%