Weaknesses of type CWE-79

28,618 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2022-0752LOWCross-site Scripting (XSS) - Generic in hestiacp/hestiacpEPSS 1.0%CVE-2017-16018—Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent URL, an attacker can EPSS 1.0%CVE-2024-29217MEDIUMApache Answer: XSS vulnerability when changing personal websiteEPSS 1.0%CVE-2022-42118MEDIUMA Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fixEPSS 1.0%CVE-2022-1782CRITICALCross-site Scripting (XSS) - Generic in erudika/paraEPSS 1.0%CVE-2023-42426MEDIUMCross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert lEPSS 1.0%CVE-2019-19336MEDIUMA cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters weEPSS 1.0%CVE-2024-23995MEDIUMCross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a EPSS 1.0%CVE-2022-31035CRITICALExternal URLs for Deployments can include javascript in argo-cdEPSS 1.0%CVE-2023-1410MEDIUMStored XSS in Graphite FunctionDescription tooltipEPSS 1.0%CVE-2020-8208—Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.EPSS 1.0%CVE-2022-21719MEDIUMReflected XSS using reload button in GLPIEPSS 1.0%CVE-2021-32670HIGHReflected cross-site scripting issue in DatasetteEPSS 1.0%CVE-2019-10177MEDIUMA stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user inEPSS 1.0%CVE-2024-49038CRITICALMicrosoft Copilot Studio Elevation Of Privilege VulnerabilityEPSS 1.0%CVE-2024-43788MEDIUMDOM Clobbering Gadget found in Webpack's AutoPublicPathRuntimeModule that leads to Cross-site Scripting (XSS)EPSS 1.0%CVE-2024-11412MEDIUMShine PDF Embeder <= 1.0 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 1.0%CVE-2022-39331MEDIUMCross-site Scripting (XSS) in Nexcloud Desktop ClientEPSS 1.0%CVE-2025-2127MEDIUMJoomlaUX JUX Real Estate realties cross site scriptingEPSS 1.0%CVE-2024-35627MEDIUMtileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.EPSS 1.0%