Weaknesses of type CWE-79

28,384 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2018-0223A vulnerability in DesktopServlet in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attEPSS 1.7%CVE-2018-0144A vulnerability in the web-based management interface of Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attaEPSS 1.7%CVE-2020-1100MEDIUMMicrosoft Office SharePoint XSS VulnerabilityEPSS 1.7%CVE-2020-1101MEDIUMMicrosoft Office SharePoint XSS VulnerabilityEPSS 1.7%CVE-2020-1099MEDIUMMicrosoft Office SharePoint XSS VulnerabilityEPSS 1.7%CVE-2020-8477HIGHABB System 800xA Information Manager Remote Code ExecutionEPSS 1.7%CVE-2022-0020MEDIUMCortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web InterfaceEPSS 1.7%CVE-2025-8191MEDIUMmacrozheng mall Swagger UI index.html cross site scriptingEPSS 1.7%CVE-2021-36026MEDIUMMagento Commerce Stored Cross-site Scripting VulnerabilityEPSS 1.7%CVE-2021-3509A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStoEPSS 1.7%CVE-2021-22886Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a rEPSS 1.7%CVE-2019-16780MEDIUMStored cross-site scripting (XSS) in WordPress block editorEPSS 1.7%CVE-2022-35493MEDIUMA Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store WebEPSS 1.7%CVE-2020-26296HIGHXSS in VegaEPSS 1.7%CVE-2025-48700MEDIUMAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the ZiEPSS 1.7%KEVCVE-2021-4285LOWNagios NCPA tail.html cross site scriptingEPSS 1.7%CVE-2021-24319Bello < 1.6.0 - Authenticated Cross-Site Scripting (XSS) and XFSEPSS 1.7%CVE-2020-9737MEDIUMStored XSS in AEM's Content Repository Development EnvironmentEPSS 1.7%CVE-2020-9738MEDIUMStored XSS in AEM's Content Repository Development EnvironmentEPSS 1.7%CVE-2014-5408Nordex NC2 Cross-site ScriptingEPSS 1.7%