Weaknesses of type CWE-79

28,618 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2008-3935MEDIUMCross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbiEPSS 1.0%CVE-2024-21910MEDIUMCross-site scripting vulnerability in TinyMCE pluginsEPSS 1.0%CVE-2016-3709—Possible cross-site scripting vulnerability in libxml after commit 960f0e2.EPSS 1.0%CVE-2022-2066HIGHCross-site Scripting (XSS) - Reflected in neorazorx/facturascriptsEPSS 1.0%CVE-2022-44949MEDIUMRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?mEPSS 1.0%CVE-2021-4289LOWOpenMRS openmrs-module-referenceapplication User App Page UserAppPageController.java post cross site scriptingEPSS 1.0%CVE-2022-44950MEDIUMRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field function at /index.php?mEPSS 1.0%CVE-2023-45757—Apache bRPC: The builtin service rpcz page has an XSS attack vulnerabilityEPSS 1.0%CVE-2022-3484MEDIUMWPB Show Core - Reflected Cross-Site ScriptingEPSS 1.0%CVE-2021-25963MEDIUMShuup - Reflected XSS in Error PageEPSS 1.0%CVE-2022-44951MEDIUMRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab function at /index.phEPSS 1.0%CVE-2023-36886HIGHMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 1.0%CVE-2021-39345MEDIUMHAL <= 2.1.1 Authenticated Stored Cross-Site ScriptingEPSS 1.0%CVE-2024-30053MEDIUMAzure Migrate Cross-Site Scripting VulnerabilityEPSS 1.0%CVE-2023-2256—Product Addons & Fields for WooCommerce < 32.0.7 - Reflected Cross-Site ScriptingEPSS 1.0%CVE-2023-34121MEDIUMImproper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated EPSS 1.0%CVE-2022-2470MEDIUMCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 1.0%CVE-2020-19947CRITICALCross Site Scripting vulnerability found in Markdown Edit allows a remote attacker to execute arbitrary code via the edit parameter of the wEPSS 1.0%CVE-2020-10643MEDIUMOSIsoft PI SystemEPSS 1.0%CVE-2022-1250—LifterLMS PayPal < 1.4.0 - Reflected Cross-Site ScriptingEPSS 0.9%