Weaknesses of type CWE-79

29,217 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-46494MEDIUMCross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information viaEPSS 0.5%CVE-2024-10882MEDIUMProduct Delivery Date for WooCommerce - Lite <= 2.8.0 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2023-5810LOWflusity CMS posts.php loadPostAddForm cross site scriptingEPSS 0.5%CVE-2024-9077MEDIUMdingfangzu Order Checkout order.js cross site scriptingEPSS 0.5%CVE-2022-40408MEDIUMFeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box undEPSS 0.5%CVE-2024-0718LOWliuwy-dlsdys zhglxt HTTP POST Request edit cross site scriptingEPSS 0.5%CVE-2022-42349MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2024-2116MEDIUMChristmas Greetings <= 1.2.5 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2024-57423MEDIUMA Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid paraEPSS 0.5%CVE-2025-55420HIGHA Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET requeEPSS 0.5%CVE-2022-42362MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2026-40541CRITICALAn improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat SerEPSS 0.5%CVE-2020-9419MEDIUMMultiple stored cross-site scripting (XSS) vulnerabilities in Arcadyan Wifi routers VRV9506JAC23 allow remote attackers to inject arbitrary EPSS 0.5%CVE-2022-44463MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2025-64495HIGHOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCEEPSS 0.5%CVE-2022-42364MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-35693MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2023-1881HIGHCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.5%CVE-2022-42352MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-42354MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%