Weaknesses of type CWE-79

29,112 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-7057LOWcode-projects Faculty Management System yearlevel.php cross site scriptingEPSS 0.5%CVE-2022-37338MEDIUMWordPress Blossom Recipe Maker plugin <= 1.0.7 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.5%CVE-2010-10004LOWInformation Cards Module cross site scriptingEPSS 0.5%CVE-2022-40213MEDIUMWordPress GS Testimonial Slider plugin <= 1.9.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitiesEPSS 0.5%CVE-2022-35294—An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is tEPSS 0.5%CVE-2023-0327LOWsaemorris TheRadSystem users.php cross site scriptingEPSS 0.5%CVE-2021-4303LOWshannah Xataface Installer install_form.js.php testftp cross site scriptingEPSS 0.5%CVE-2026-23794MEDIUMApache Syncope: Reflected XSS on Enduser LoginEPSS 0.5%CVE-2024-0448MEDIUMElementor Addons by Livemesh <= 8.3.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-1296MEDIUMBrizy – Page Builder <= 2.4.40 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2021-3914—It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to coEPSS 0.5%CVE-2023-28604MEDIUMThe fluid_components (aka Fluid Components) extension before 3.5.0 for TYPO3 allows XSS via a component argument parameter, for certain {conEPSS 0.5%CVE-2025-8368MEDIUMPortabilis i-Educar pesquisa_pessoa_lst.php cross site scriptingEPSS 0.5%CVE-2023-7319MEDIUMNagios Network Analyzer < 2024R1 XSS via Percentile Calculator MenuEPSS 0.5%CVE-2022-40002MEDIUMCross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/EPSS 0.5%CVE-2025-8370MEDIUMPortabilis i-Educar educar_escolaridade_lst.php cross site scriptingEPSS 0.5%CVE-2016-15049MEDIUMNagios Log Server < 1.4.2 Dashboards Logs Table XSSEPSS 0.5%CVE-2014-125034LOWstiiv contact_app View.php render cross site scriptingEPSS 0.5%CVE-2023-33438MEDIUMA stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web scriEPSS 0.5%CVE-2026-42338MEDIUMip-address: XSS in Address6 HTML-emitting methodsEPSS 0.5%