Weaknesses of type CWE-79

29,220 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-42365MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-42364MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-44463MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2026-40607HIGHMantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner ColumnEPSS 0.5%CVE-2022-35693MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2026-47324MEDIUMStored XSS in Multiple Points in ProjectsAndPrograms school-management-systemEPSS 0.5%CVE-2022-44467MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-42352MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2024-10850MEDIUMRazorpay Payment Button for Elementor <= 1.2.5 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2022-42350MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2025-64495HIGHOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCEEPSS 0.5%CVE-2023-25929MEDIUMIBM Cognos Analytics cross-site scriptingEPSS 0.5%CVE-2026-34463HIGHMantisBT has Stored HTML Injection/XSS via Clone Issue FormEPSS 0.5%CVE-2022-44471MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2023-2853MEDIUMXSS in SoftMed's SelfPatronEPSS 0.5%CVE-2023-51447MEDIUMDecidim vulnerable to cross-site scripting (XSS) in the dynamic file uploadsEPSS 0.5%CVE-2025-64338MEDIUMClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection NameEPSS 0.5%CVE-2024-3141LOWClavister E10/E80 Misc Settings Page MiscSettings cross site scriptingEPSS 0.5%CVE-2023-1881HIGHCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.5%CVE-2024-2116MEDIUMChristmas Greetings <= 1.2.5 - Reflected Cross-Site ScriptingEPSS 0.5%