Weaknesses of type CWE-79

29,217 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-36863MEDIUMWordPress Quiz And Survey Master plugin <= 7.3.4 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2024-0612MEDIUMContent Views <= 3.6.2 - Authenticated(Administrator+) Stored Cross-Site Scripting via settingsEPSS 0.5%CVE-2026-64971MEDIUMReflected XSS in ATutorEPSS 0.5%CVE-2024-30885MEDIUMReflected Cross-Site Scripting (XSS) vulnerability in HadSky v7.6.3, allows remote attackers to execute arbitrary code and obtain sensitive EPSS 0.5%CVE-2022-44590MEDIUMWordPress Simple Video Embedder plugin <= 2.2 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2024-2200MEDIUMContact Form by BestWebSoft <= 4.2.8 - Reflected Cross-Site Scripting via cntctfrm_contact_subjectEPSS 0.5%CVE-2022-25781MEDIUMReflected XSS issues in GateManagerEPSS 0.5%CVE-2024-21636MEDIUMview_component Cross-site Scripting vulnerabilityEPSS 0.5%CVE-2026-9838MEDIUMICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' ParameterEPSS 0.5%CVE-2024-1412MEDIUMMemberpress <= 1.11.24 - Reflected Cross-Site Scripting via message and errorEPSS 0.5%CVE-2023-3532HIGHCross-site Scripting (XSS) - Stored in outline/outlineEPSS 0.5%CVE-2020-37245HIGHWordPress Plugin Supsystic Digital Publications 1.6.9 Path Traversal XSSEPSS 0.5%CVE-2021-32009MEDIUMMissing XSS guards on firmware pageEPSS 0.5%CVE-2026-42523CRITICALJenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the featuEPSS 0.5%CVE-2026-55105HIGHJoplin: Fountain embeds allow arbitrary script execution in published notes and the note viewerEPSS 0.5%CVE-2026-21269MEDIUMColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2026-87915HIGHPopup Maker <= 1.24.0 - Unauthenticated Stored Cross-Site Scripting via values[Name] ParameterEPSS 0.5%CVE-2023-2735MEDIUMGroundhogg <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2024-10882MEDIUMProduct Delivery Date for WooCommerce - Lite <= 2.8.0 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2022-44380MEDIUMSnipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.EPSS 0.5%