Weaknesses of type CWE-79

29,250 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-0308HIGHCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.5%CVE-2023-0309HIGHCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.5%CVE-2021-44461MEDIUMCross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are able to control theEPSS 0.5%CVE-2024-6523MEDIUMZKTeco BioTime system-group-add cross site scriptingEPSS 0.5%CVE-2026-86738CRITICALSnipe-IT before 8.7.0 CSS Injection via Custom CSSEPSS 0.5%CVE-2024-7398MEDIUMConcrete CMS Stored XSS Vulnerability in Calendar Event Addition FeatureEPSS 0.5%CVE-2024-12998MEDIUMcode-projects Online Car Rental System GET Parameter index.php cross site scriptingEPSS 0.5%CVE-2025-3434HIGHSMTP for Amazon SES – YaySMTP <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email LogsEPSS 0.5%CVE-2023-2169MEDIUMTaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-24195MEDIUMOnline Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.EPSS 0.5%CVE-2026-5808MEDIUMopenstatusHQ openstatus Onboarding Endpoint client.tsx cross site scriptingEPSS 0.5%CVE-2025-59545CRITICALDNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt moduleEPSS 0.5%CVE-2022-43263MEDIUMA cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to execute arbitraEPSS 0.5%CVE-2026-15715MEDIUMSourceCodester Class and Exam Timetabling System exam.php cross site scriptingEPSS 0.5%CVE-2023-24192MEDIUMOnline Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.EPSS 0.5%CVE-2024-34231HIGHA cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scrEPSS 0.5%CVE-2023-43342MEDIUMCross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted scrEPSS 0.5%CVE-2023-2170MEDIUMTaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2022-46684MEDIUMJenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTMLEPSS 0.5%CVE-2024-4430MEDIUMBeaver Builder <= 2.8.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via photo widget crop attributeEPSS 0.5%