Weaknesses of type CWE-79

29,160 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-1956MEDIUMWPB Show Core < 2.7 - Reflected XSSEPSS 0.5%CVE-2024-23191MEDIUMUpsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To expEPSS 0.5%CVE-2024-2259MEDIUMReflected XXS Vulnerability in InstaRISPACS SoftwareEPSS 0.5%CVE-2023-46744MEDIUMStored Cross-site Scripting in SquidexEPSS 0.5%CVE-2024-23895HIGHCross-Site Scripting (XSS) vulnerability in Cups EasyEPSS 0.5%CVE-2024-43737MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2024-43718MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2025-51990MEDIUMXWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specEPSS 0.5%CVE-2024-47925HIGHTecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.5%CVE-2017-5256—In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System DeEPSS 0.5%CVE-2026-25616MEDIUMBlesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.EPSS 0.5%CVE-2024-40631HIGHCross-site Scripting (XSS) in media embed element when using custom URL parsers in plate mediaEPSS 0.5%CVE-2024-37384MEDIUMRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.EPSS 0.5%CVE-2026-66494HIGHJoomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0EPSS 0.5%CVE-2024-53481MEDIUMA Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers toEPSS 0.5%CVE-2024-51486MEDIUMStored Cross-Site Scripting in AmpacheEPSS 0.5%CVE-2023-0110HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.5%CVE-2023-0107MEDIUMCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.5%CVE-2026-78438HIGHW3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background MutatorEPSS 0.5%CVE-2023-0949MEDIUMCross-site Scripting (XSS) - Reflected in modoboa/modoboaEPSS 0.5%