Weaknesses of type CWE-79

29,112 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-50727MEDIUMResque vulnerable to reflected XSS in Queue EndpointEPSS 0.5%CVE-2022-36341MEDIUMWordPress AS – Create Pinterest Pinboard Pages plugin <= 1.0 - Authenticated plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2020-20725MEDIUMCross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in adEPSS 0.5%CVE-2026-73781HIGHAuthenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Management InterfaceEPSS 0.5%CVE-2025-34318MEDIUMIPFire < v2.29 Stored XSS via DNS Creation (proxy.cgi)EPSS 0.5%CVE-2023-1349LOWHsycms Add Category Module cate.php cross site scriptingEPSS 0.5%CVE-2023-23951MEDIUMAbility to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the applicationEPSS 0.5%CVE-2022-42100MEDIUMKLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply-form.EPSS 0.5%CVE-2022-43082MEDIUMA cross-site scripting (XSS) vulnerability in /fastfood/purchase.php of Fast Food Ordering System v1.0 allows attackers to execute arbitraryEPSS 0.5%CVE-2013-10022LOWBestWebSoft Contact Form Plugin contact_form.php cntctfrm_check_form cross site scriptingEPSS 0.5%CVE-2023-1316MEDIUMCross-site Scripting (XSS) - Stored in osticket/osticketEPSS 0.5%CVE-2023-4890MEDIUMJQuery Accordion Menu Widget <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2023-23950MEDIUMUser’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.EPSS 0.5%CVE-2020-21485MEDIUMCross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browEPSS 0.5%CVE-2022-41376MEDIUMMetro UI v4.4.0 to v4.5.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Javascript function.EPSS 0.5%CVE-2022-32280MEDIUMWordPress XO Slider plugin <= 3.3.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2022-42099MEDIUMKLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subject input.EPSS 0.5%CVE-2024-51490MEDIUMStored Cross-Site Scripting in AmpacheEPSS 0.5%CVE-2023-6366HIGHWhatsUp Gold Stored Cross-Site Scripting (XSS) via Alert CenterEPSS 0.5%CVE-2023-6364HIGHWhatsUp Gold Stored Cross-Site Scripting (XSS) via DashboardEPSS 0.5%