Weaknesses of type CWE-79

29,274 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2024-32409HIGHAn issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.EPSS 0.5%CVE-2026-11982MEDIUMStored XSS via missing XSS safety check in Admin2 Pages API partial validationEPSS 0.5%CVE-2022-41980MEDIUMWordPress Mantenimiento web plugin <= 0.13 - Auth. Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2026-62829MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.5%CVE-2024-42515CRITICALGlossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <EPSS 0.5%CVE-2025-68669CRITICAL5ire vulnerable to Remote Code Execution (RCE) via mermaidEPSS 0.5%CVE-2024-22776MEDIUMWallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring sEPSS 0.5%CVE-2026-63671HIGH@nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configurationEPSS 0.5%CVE-2026-78615MEDIUMWatchGuard Dimension Reflected DOM-Based XSS in Report Detail PageEPSS 0.5%CVE-2024-13034MEDIUMcode-projects Chat System update_user.php cross site scriptingEPSS 0.5%CVE-2024-23172MEDIUMAn issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.EPSS 0.5%CVE-2022-39027MEDIUMe-Excellence Inc. U-Office Force - Stored XSSEPSS 0.5%CVE-2025-2714MEDIUMJoomlaUX JUX Real Estate addagent cross site scriptingEPSS 0.5%CVE-2026-77830HIGHSpam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label PlaceholderEPSS 0.5%CVE-2024-37629MEDIUMSummerNote v0.9.1 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.EPSS 0.5%CVE-2024-27902MEDIUMCross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP applications based on SAPGUI for HTML (WebGUI)EPSS 0.5%CVE-2026-82535MEDIUMChamilo LMS Stored XSS via Survey Answer Submission in reporting.phpEPSS 0.5%CVE-2022-39026MEDIUMe-Excellence Inc. U-Office Force - Stored XSSEPSS 0.5%CVE-2023-45207MEDIUMAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains EPSS 0.5%CVE-2026-42849CRITICALauthentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeoverEPSS 0.5%