Weaknesses of type CWE-79

29,081 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-20632MEDIUMCisco Enterprise Chat and Email Cross-Site Scripting VulnerabilityEPSS 0.5%CVE-2022-39375MEDIUMCross-Site Scripting (XSS) through public RSS feed in GLPIEPSS 0.5%CVE-2026-15217HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2023-5665MEDIUMPayment Forms for Paystack <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2025-27654MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Cross Site Scripting (XSS) V-2023-0EPSS 0.5%CVE-2025-27653MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Preauthenticated Cross Site ScriptiEPSS 0.5%CVE-2026-84370HIGHSVGO: removeScripts allows executable links through namespace and control-character bypassesEPSS 0.5%CVE-2026-82089HIGHThe wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a EPSS 0.5%CVE-2026-15216HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2021-39332MEDIUMBusiness Manager – WordPress ERP, HR, CRM, and Project Management Plugin <= 1.4.5 Authenticated Stored Cross-Site ScriptingEPSS 0.5%CVE-2025-27637MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016.EPSS 0.5%CVE-2022-35297—The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being EPSS 0.5%CVE-2024-45613MEDIUMCKEditor 5 has Cross-site Scripting vulnerability in the clipboard packageEPSS 0.5%CVE-2020-35698MEDIUMThinkific Thinkific Online Course Creation Platform 1.0 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (rEPSS 0.5%CVE-2022-42348MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-4413MEDIUMCross-site Scripting (XSS) - Reflected in nuxt/frameworkEPSS 0.5%CVE-2019-25092LOWNakiami Mellivora Admin Panel user.inc.php print_user_ip_log cross site scriptingEPSS 0.5%CVE-2023-53155HIGHgoform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.EPSS 0.5%CVE-2025-66562HIGHTUUI vulnerable to Remote Code Execution (RCE) via XSS in Markdown ECharts RenderingEPSS 0.5%CVE-2022-43120MEDIUMA cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute EPSS 0.5%