Weaknesses of type CWE-79

29,093 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-27070MEDIUMA stored cross-site scripting (XSS) vulnerability in TotalJS OpenPlatform commit b80b09d allows attackers to execute arbitrary web scripts oEPSS 0.5%CVE-2024-36193MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2024-9614MEDIUMConstant Contact Forms by MailMunch <= 2.1.2 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2023-5817MEDIUMNeon text <= 1.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-36209MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2024-36198MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2023-48858MEDIUMA Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web scripEPSS 0.5%CVE-2024-36195MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2023-22475MEDIUMCross-Site Scripting in Canarytoken historyEPSS 0.5%CVE-2022-28979MEDIUMLiferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before service pack 3 was discoEPSS 0.5%CVE-2025-2214MEDIUMMicroweber Settings index.php cross site scriptingEPSS 0.5%CVE-2024-45517MEDIUMAn issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of thEPSS 0.5%CVE-2025-0721MEDIUMneedyamin image_gallery view.php cross site scriptingEPSS 0.5%CVE-2024-36199MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2014-125078LOWyanheven console horizon.instances.js cross site scriptingEPSS 0.5%CVE-2024-11225MEDIUMPremium Packages – Sell Digital Products Securely <= 5.9.3 - Reflected Cross-Site Scripting via add_query_argEPSS 0.5%CVE-2024-40474HIGHA Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.EPSS 0.5%CVE-2023-3660LOWCampcodes Retro Cellphone Online Store add_user_modal.php cross site scriptingEPSS 0.5%CVE-2021-4310LOW01-Scripts 01-Artikelsystem 01article.php cross site scriptingEPSS 0.5%CVE-2026-73042CRITICALSiYuan before v3.7.4 Remote Code Execution via Menu MetadataEPSS 0.5%