Weaknesses of type CWE-79

29,081 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2026-88869CRITICALAVideo AD_Server Stored XSS via log.php label parameterEPSS 0.5%CVE-2022-40178—A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 0.5%CVE-2023-25059MEDIUMWordPress avalex Plugin <= 3.0.3 is vulnerable to Cross Site Scripting (XSS)EPSS 0.5%CVE-2026-3368HIGHInjection Guard <= 1.2.9 - Unauthenticated Stored Cross-Site Scripting via Query Parameter NameEPSS 0.5%CVE-2023-4406MEDIUMXSS in KC Group's E-Commerce SoftwareEPSS 0.5%CVE-2026-13040HIGHNEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' ParameterEPSS 0.5%CVE-2023-25172MEDIUMDiscourse vulnerable to Cross-site Scripting - user name displayed on postEPSS 0.5%CVE-2023-48300MEDIUMEmbed Privacy missing escaping for show_all attribute in opt-out shortcodeEPSS 0.5%CVE-2022-31468MEDIUMOX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.EPSS 0.5%CVE-2026-16655HIGHFluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` MemberEPSS 0.5%CVE-2026-83593HIGHWPBot <= 8.7.3 - Unauthenticated Stored Cross-Site Scripting via 'conversation' ParameterEPSS 0.5%CVE-2023-5378HIGHStored XSS in SmodBIP and MegaBIPEPSS 0.5%CVE-2024-26542MEDIUMCross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrEPSS 0.5%CVE-2025-52668HIGHImproper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential iEPSS 0.5%CVE-2026-9292HIGHRockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site ScriptingEPSS 0.5%CVE-2022-23707—An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index paEPSS 0.5%CVE-2024-47527HIGHLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device-dependencies.inc.phpEPSS 0.5%CVE-2026-12142HIGHNEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array ParameterEPSS 0.5%CVE-2026-75528HIGHBroken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link LogEPSS 0.5%CVE-2026-89412HIGHTranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion PanelEPSS 0.5%