Weaknesses of type CWE-79

28,612 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2020-2497—Cross-site scripting vulnerability in QTS and QuTS heroEPSS 1.0%CVE-2020-8176—A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shopEPSS 1.0%CVE-2022-39207MEDIUMPersistent XSS in OneDevEPSS 1.0%CVE-2020-25628—The filter in the tag manager required extra sanitizing to prevent a reflected XSS risk. This affects 3.9 to 3.9.1, 3.8 to 3.8.4, 3.7 to 3.7EPSS 1.0%CVE-2022-23081—Openlibrary - Reflected XSSEPSS 1.0%CVE-2020-1721—A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID duEPSS 1.0%CVE-2024-30929HIGHCross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the 'back' Parameter in playlisEPSS 1.0%CVE-2022-39332MEDIUMCross-site scripting (XSS) in Nextcloud Desktop Client EPSS 1.0%CVE-2022-44947MEDIUMRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feature at /index.php?moEPSS 1.0%CVE-2024-34064MEDIUMJinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterEPSS 1.0%CVE-2023-43091CRITICALGnome-maps: gnome maps is vulnerable to a code injection attack (similar to xss) via its service.jsonEPSS 1.0%CVE-2022-32923MEDIUMA correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS VenEPSS 1.0%CVE-2022-23494MEDIUMCross-site scripting vulnerability in TinyMCE alertsEPSS 1.0%CVE-2022-2515MEDIUMSimple Banner <= 2.11.0 - Authenticated Stored Cross-Site ScriptingEPSS 1.0%CVE-2022-39333MEDIUMCross-site scripting (XSS) in Nextcloud Desktop ClientEPSS 1.0%CVE-2018-14784—NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-sitEPSS 1.0%CVE-2017-16006—Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute jEPSS 1.0%CVE-2022-43167MEDIUMA stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_alerts) of Rukovoditel vEPSS 1.0%CVE-2026-40878LOWmailcow-dockerized Login Page has Reflected Parameter Injection / Wrong-Context XSS EscapingEPSS 1.0%CVE-2022-0565HIGHCross-site Scripting in pimcore/pimcoreEPSS 1.0%