Weaknesses of type CWE-79

29,112 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2025-8370MEDIUMPortabilis i-Educar educar_escolaridade_lst.php cross site scriptingEPSS 0.5%CVE-2014-125034LOWstiiv contact_app View.php render cross site scriptingEPSS 0.5%CVE-2016-15049MEDIUMNagios Log Server < 1.4.2 Dashboards Logs Table XSSEPSS 0.5%CVE-2023-6217HIGHMOVEit Transfer XSS via MOVEit GatewayEPSS 0.5%CVE-2024-30926MEDIUMCross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/kiosks.inc component.EPSS 0.5%CVE-2023-7323MEDIUMNagios Log Server < 2024R1 XSS via Create User FunctionEPSS 0.5%CVE-2014-125031LOWkirill2485 TekNet loggedin.php cross site scriptingEPSS 0.5%CVE-2014-125039LOWkkokko NeoXplora Trainer cross site scriptingEPSS 0.5%CVE-2022-47509MEDIUMSolarWinds Platform Incorrect Input Neutralization VulnerabilityEPSS 0.5%CVE-2023-34244MEDIUMGLPI vulnerable to reflected XSS in search pagesEPSS 0.5%CVE-2022-40373MEDIUMCross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.EPSS 0.5%CVE-2020-36858MEDIUMNagios Log Server < 2.1.6 XSS via Create User, Edit User, & Manage Host Lists PagesEPSS 0.5%CVE-2025-8369MEDIUMPortabilis i-Educar educar_avaliacao_desempenho_lst.php cross site scriptingEPSS 0.5%CVE-2025-1949MEDIUMZZCMS URL register_nodb.php cross site scriptingEPSS 0.5%CVE-2023-35776MEDIUMWordPress Sermon'e – Sermons Online Plugin <= 1.0.0 is vulnerable to Cross Site Scripting (XSS)EPSS 0.5%CVE-2022-40000MEDIUMCross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the adminEPSS 0.5%CVE-2023-33438MEDIUMA stored Cross-site scripting (XSS) vulnerability in Wolters Kluwer TeamMate+ 35.0.11.0 allows remote attackers to inject arbitrary web scriEPSS 0.5%CVE-2023-7321MEDIUMNagios Log Server < 2.1.14 XSS via Snapshots PageEPSS 0.5%CVE-2025-8368MEDIUMPortabilis i-Educar pesquisa_pessoa_lst.php cross site scriptingEPSS 0.5%CVE-2024-36173MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%