Weaknesses of type CWE-79

29,115 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-31223HIGHDradis before 4.8.0 allows persistent XSS by authenticated author users, related to avatars.EPSS 0.5%CVE-2023-43647MEDIUMbaserCMS Cross-site Scripting vulnerability in File upload FeatureEPSS 0.5%CVE-2023-25062MEDIUMWordPress Pinpoint Booking System Plugin <= 2.9.9.2.8 is vulnerable to Cross Site Scripting (XSS)EPSS 0.5%CVE-2021-25967MEDIUMCKAN - Stored Cross-Site Scripting (XSS) via SVG File UploadEPSS 0.5%CVE-2022-20657MEDIUMCisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Cross-Site Scripting VulnerabilityEPSS 0.5%CVE-2024-0254MEDIUM(Simply) Guest Author Name <= 4.34 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-0010MEDIUMPAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect PortalEPSS 0.5%CVE-2024-1237MEDIUMElementor Header & Footer Builder <= 1.6.24 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2026-54158CRITICALSiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()EPSS 0.5%CVE-2026-84673HIGHJenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through StaplerEPSS 0.5%CVE-2022-41435MEDIUMOpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /EPSS 0.5%CVE-2019-25093LOWdragonexpert Recent Threads on Index Setting hooks.php recentthread_list_threads cross site scriptingEPSS 0.5%CVE-2024-6447HIGHFULL <= 3.1.12 - Unauthenticated Stored Cross-Site Scripting via License Plan ParameterEPSS 0.5%CVE-2024-1392MEDIUMElementor Addon Elements <= 1.12.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dual Button WidgetEPSS 0.5%CVE-2022-20631MEDIUMCisco Enterprise Chat and Email Cross-Site Scripting VulnerabilityEPSS 0.5%CVE-2025-3489MEDIUMNababur Simple-User-Management-System register.php cross site scriptingEPSS 0.5%CVE-2024-45962MEDIUMOctober 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the filEPSS 0.5%CVE-2024-12870MEDIUMStored Cross-site Scripting (XSS) in infiniflow/ragflowEPSS 0.5%CVE-2024-3244MEDIUMEmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2026-27870MEDIUMCROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC OF TELDATEPSS 0.5%