Weaknesses of type CWE-79

29,081 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-49593MEDIUMIn Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor tEPSS 0.5%CVE-2022-40712MEDIUMAn issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.EPSS 0.5%CVE-2023-7075LOWcode-projects Point of Sales and Inventory Management System checkout.php cross site scriptingEPSS 0.5%CVE-2022-25276MEDIUMThe Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of thEPSS 0.5%CVE-2022-34315MEDIUMIBM CICS TX cross-site scriptingEPSS 0.5%CVE-2023-1243MEDIUMCross-site Scripting (XSS) - Stored in answerdev/answerEPSS 0.5%CVE-2024-44085MEDIUMONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoEPSS 0.5%CVE-2023-1239MEDIUMCross-site Scripting (XSS) - Reflected in answerdev/answerEPSS 0.5%CVE-2024-7874MEDIUMXSS in Tungsten Automation TotalAgilityEPSS 0.5%CVE-2017-7534—OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user inEPSS 0.5%CVE-2024-11246MEDIUMcode-projects Farmacia adicionar-cliente.php cross site scriptingEPSS 0.5%CVE-2025-27637MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016.EPSS 0.5%CVE-2025-24853HIGHApache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processingEPSS 0.5%CVE-2022-39375MEDIUMCross-Site Scripting (XSS) through public RSS feed in GLPIEPSS 0.5%CVE-2024-0449MEDIUMArtiBot Free Chat Bot for WordPress WebSites <= 1.1.6 - Authenticated (Admin+) Cross-Site ScriptingEPSS 0.5%CVE-2022-36137MEDIUMChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.EPSS 0.5%CVE-2023-33548MEDIUMCross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to ruEPSS 0.5%CVE-2023-23627MEDIUMSanitize vulnerable to Cross-site Scripting via Improper neutralization of `noscript` elementEPSS 0.5%CVE-2026-15217HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2026-40598MEDIUMMantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update PageEPSS 0.5%