Weaknesses of type CWE-79

29,250 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-41599MEDIUMCross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload methodEPSS 0.5%CVE-2023-0624MEDIUMOrangeScrum version 2.0.11 allows an external attacker to obtain arbitrary user accounts from the application. This is possible because the EPSS 0.5%CVE-2022-45990MEDIUMA cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitraEPSS 0.5%CVE-2026-15715MEDIUMSourceCodester Class and Exam Timetabling System exam.php cross site scriptingEPSS 0.5%CVE-2024-1749LOWBdtask Bhojon Best Restaurant Management Software Message Page message cross site scriptingEPSS 0.5%CVE-2025-34310MEDIUMIPFire < v2.29 Stored XSS via Quality of Service (QoS) SettingsEPSS 0.5%CVE-2025-34316MEDIUMIPFire < v2.29 Stored XSS via Mail Server SettingsEPSS 0.5%CVE-2024-12395MEDIUMWooCommerce Additional Fees On Checkout (Free) <= 1.4.7 - Reflected Cross-Site Scripting via 'number'EPSS 0.5%CVE-2023-3555LOWGZ Scripts PHP Vacation Rental Script preview.php cross site scriptingEPSS 0.5%CVE-2023-27489HIGHStored cross site scripting via SVG file upload in Kiwi TCMSEPSS 0.5%CVE-2022-20663MEDIUMSecure Network Analytics Cross-Site Scripting VulnerabilityEPSS 0.5%CVE-2024-11678MEDIUMCodeAstro Hospital Management System his_doc_register_patient.php cross site scriptingEPSS 0.5%CVE-2023-3554LOWGZ Scripts GZ Forum Script preview.php cross site scriptingEPSS 0.5%CVE-2024-23187MEDIUMContent-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. AttEPSS 0.5%CVE-2022-27503—Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9EPSS 0.5%CVE-2025-34302MEDIUMIPFire < v2.29 Stored XSS via Service CreationEPSS 0.5%CVE-2026-48015MEDIUMShopware: Stored XSS via SVG file upload — no SVG sanitizationEPSS 0.5%CVE-2024-30889MEDIUMCross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code viEPSS 0.5%CVE-2023-31177MEDIUMImproper neutralizataion of input could lead to execution of arbitrary codeEPSS 0.5%CVE-2022-29811MEDIUMIn JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.EPSS 0.5%