Weaknesses of type CWE-79

28,384 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-1906—Copyright Proof <= 4.16 - Reflected Cross-Site-ScriptingEPSS 1.1%CVE-2022-1557—ULeak Security & Monitoring <= 1.2.3 - Subscriber+ Stored Cross-Site ScriptingEPSS 1.1%CVE-2024-21394HIGHDynamics 365 Field Service Spoofing VulnerabilityEPSS 1.1%CVE-2021-24153—Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 1.1%CVE-2022-41473MEDIUMRPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.EPSS 1.1%CVE-2025-22466HIGHReflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtaEPSS 1.1%CVE-2022-29618—Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, aEPSS 1.1%CVE-2024-45061HIGHA cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A specially crafted HTEPSS 1.1%CVE-2019-14881MEDIUMA vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user email is displayed.EPSS 1.1%CVE-2022-24851HIGHStored XSS and path traversal in LDAPAccountManager/lamEPSS 1.1%CVE-2022-23520MEDIUMrails-html-sanitizer contains an incomplete fix for an XSS vulnerabilityEPSS 1.1%CVE-2025-2609HIGHMagnusBilling Stored Cross-Site Scripting in Login LogsEPSS 1.1%CVE-2021-32681MEDIUMImproper escaping of HTML ('Cross-site Scripting') in Wagtail StreamField blocksEPSS 1.1%CVE-2021-24985—Easy Forms for Mailchimp < 6.8.6 - Reflected Cross-Site ScriptingEPSS 1.1%CVE-2024-33299MEDIUMCross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last NameEPSS 1.1%CVE-2024-33297MEDIUMCross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal EPSS 1.1%CVE-2019-12644MEDIUMCisco Identity Services Engine Cross-Site Scripting VulnerabilityEPSS 1.1%CVE-2019-3754MEDIUMDell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 and Dell EMC VNXe320EPSS 1.1%CVE-2026-42253MEDIUMApache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message PropertiesEPSS 1.1%CVE-2021-32733MEDIUMXSS in Nextcloud Text applicationEPSS 1.1%