Weaknesses of type CWE-79

29,274 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-0963MEDIUMCalculated Fields Form <= 1.2.52 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-1875MEDIUMCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.5%CVE-2023-0747MEDIUMCross-site Scripting (XSS) - Stored in btcpayserver/btcpayserverEPSS 0.5%CVE-2022-20831MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2022-20833MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2024-50837MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management System Project 1.0. EPSS 0.5%CVE-2024-35583MEDIUMA cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scrEPSS 0.5%CVE-2022-20836MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2024-3489MEDIUMExclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired TitleEPSS 0.5%CVE-2022-32776MEDIUMWordPress Advanced Ads – Ad Manager & AdSense plugin <= 1.31.1 - Auth. Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2022-23637MEDIUMStored Cross-Site-Scripting (XSS) in Markdown EditorEPSS 0.5%CVE-2023-2103MEDIUMCross-site Scripting (XSS) - Stored in alextselegidis/easyappointmentsEPSS 0.5%CVE-2026-11982MEDIUMStored XSS via missing XSS safety check in Admin2 Pages API partial validationEPSS 0.5%CVE-2023-1879MEDIUMCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.5%CVE-2022-20872MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2024-42834MEDIUMA stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows aEPSS 0.5%CVE-2024-10880MEDIUMJobBoardWP – Job Board Listings and Submissions <= 1.3.0 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2022-27979MEDIUMA cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadEPSS 0.5%CVE-2022-20834MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2024-53986LOWPossible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0EPSS 0.5%