Weaknesses of type CWE-79

28,619 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-34644MEDIUMMultiplayer Games <= 3.7 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2017-16019—GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-EPSS 0.9%CVE-2022-2685LOWSourceCodester Interview Management System addQuestion.php cross site scriptingEPSS 0.9%CVE-2023-52329MEDIUMCertain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an atEPSS 0.9%CVE-2023-7312MEDIUMNagios Fusion < 4.2.0 Email Settings Stored XSS via SMTP/sendmailEPSS 0.9%CVE-2026-7569HIGHQuest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass VulnerabilityEPSS 0.9%CVE-2026-9780HIGHQuest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass VulnerabilityEPSS 0.9%CVE-2023-38164HIGHMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 0.9%CVE-2022-1087LOWhtmly Edit Profile Module cross site scriptingEPSS 0.9%CVE-2025-4859MEDIUMD-Link DAP-2695 MAC Bypass Settings Page adv_macbypass.php cross site scriptingEPSS 0.9%CVE-2019-10957—Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote auEPSS 0.9%CVE-2020-25631—A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapEPSS 0.9%CVE-2017-15125MEDIUMA flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTEPSS 0.9%CVE-2020-8245—Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, EPSS 0.9%CVE-2022-24870HIGHStored Cross-site Scripting in Combodo iTopEPSS 0.9%CVE-2023-21565HIGHAzure DevOps Server Spoofing VulnerabilityEPSS 0.9%CVE-2024-33905MEDIUMIn Telegram WebK before 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type.EPSS 0.9%CVE-2022-36107MEDIUMStored Cross-Site Scripting via FileDumpControllerEPSS 0.9%CVE-2020-15161MEDIUMPotential XSS in PrestaShopEPSS 0.9%CVE-2019-14884MEDIUMA vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal eEPSS 0.9%