Weaknesses of type CWE-79

29,081 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2025-52668HIGHImproper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential iEPSS 0.5%CVE-2022-40178—A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 0.5%CVE-2026-9292HIGHRockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site ScriptingEPSS 0.5%CVE-2026-89412HIGHTranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion PanelEPSS 0.5%CVE-2026-13040HIGHNEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' ParameterEPSS 0.5%CVE-2023-25172MEDIUMDiscourse vulnerable to Cross-site Scripting - user name displayed on postEPSS 0.5%CVE-2022-3441MEDIUMRock Convert < 2.11.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-0346LOWCodeAstro Vehicle Booking System Feedback Page user-give-feedback.php cross site scriptingEPSS 0.5%CVE-2023-0289HIGHCross-site Scripting (XSS) - Stored in craigk5n/webcalendarEPSS 0.5%CVE-2023-23011MEDIUMCross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.EPSS 0.5%CVE-2022-40712MEDIUMAn issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.EPSS 0.5%CVE-2021-24595—WP Cookie Choice <= 1.1.0 - CSRF to Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-1239MEDIUMCross-site Scripting (XSS) - Reflected in answerdev/answerEPSS 0.5%CVE-2024-49593MEDIUMIn Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor tEPSS 0.5%CVE-2023-50725MEDIUMResque vulnerable to reflected XSS in resque-web failed and queues listsEPSS 0.5%CVE-2024-23188MEDIUMMaliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. CoEPSS 0.5%CVE-2023-2566HIGHCross-site Scripting (XSS) - Stored in openemr/openemrEPSS 0.5%CVE-2023-7075LOWcode-projects Point of Sales and Inventory Management System checkout.php cross site scriptingEPSS 0.5%CVE-2024-30884HIGHReflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and oEPSS 0.5%CVE-2023-43879MEDIUMRite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the GEPSS 0.5%