Weaknesses of type CWE-79

28,384 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-47488MEDIUMCross Site Scripting vulnerability in Combodo iTop v.3.1.0-2-11973 allows a local attacker to obtain sensitive information via a crafted scrEPSS 1.2%CVE-2020-5142—A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to sEPSS 1.2%CVE-2017-6764—A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) 9.5(1) could allow an authenticated, remoteEPSS 1.2%CVE-2021-24429—Salon Booking System < 6.3.1 - Unauthenticated Stored Cross-Site Scripting (XSS)EPSS 1.2%CVE-2022-3506MEDIUMCross-site Scripting (XSS) - Stored in barrykooij/related-posts-for-wpEPSS 1.2%CVE-2023-38121HIGHInductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution VulnerabilityEPSS 1.2%CVE-2022-46073MEDIUMHelmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).EPSS 1.2%CVE-2024-8696HIGHA remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.EPSS 1.2%CVE-2022-1555HIGHDOM XSS in microweber ver 1.2.15 in microweber/microweberEPSS 1.2%CVE-2017-12212—A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected cross-EPSS 1.2%CVE-2021-24304—Newsmag < 5.0 - Unauthenticated Reflected Cross-site Scripting (XSS)EPSS 1.2%CVE-2017-6762—A vulnerability in the web-based management interface of Cisco Jabber Guest Server 10.6(9), 11.0(0), and 11.0(1) could allow an unauthenticaEPSS 1.2%CVE-2017-6761—A vulnerability in the web-based management interface of Cisco Finesse 10.6(1) and 11.5(1) could allow an unauthenticated, remote attacker tEPSS 1.2%CVE-2022-20659MEDIUMCisco Prime Infrastructure and Evolved Programmable Network Manager Cross-Site Scripting VulnerabilityEPSS 1.2%CVE-2020-1766LOWImproper handling of uploaded inline imagesEPSS 1.2%CVE-2024-4405HIGHXiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution VulnerabilityEPSS 1.2%CVE-2018-15393MEDIUMCisco Content Security Management Appliance (SMA) Cross-Site Scripting VulnerabilityEPSS 1.2%CVE-2021-24994—WPvivid Backup and Migration Plugin < 0.9.69 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2024-11432MEDIUMSuevaFree Essential Kit <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 1.2%CVE-2025-5966HIGHStored XSSEPSS 1.2%