Weaknesses of type CWE-79

28,619 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-24365—Admin Columns Free (< 4.3.2) & Pro (< 5.5.2) - Authenticated Stored Cross-Site Scripting (XSS) in Custom FieldEPSS 0.9%CVE-2021-39354MEDIUMEasy Digital Downloads <= 2.11.2 Authenticated Reflected Cross-Site ScriptingEPSS 0.9%CVE-2020-15161MEDIUMPotential XSS in PrestaShopEPSS 0.9%CVE-2021-24317—Listeo < 1.6.11 - Multiple XSS & XFS vulnerabilitiesEPSS 0.9%CVE-2019-14884MEDIUMA vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal eEPSS 0.9%CVE-2020-10748—A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flawEPSS 0.9%CVE-2021-4284LOWOpenMRS HTML Form Entry UI Framework Integration Module cross site scriptingEPSS 0.9%CVE-2021-39340MEDIUMNotification – Custom Notifications and Alerts for WordPress <= 7.2.4 Authenticated Stored Cross-Site ScriptingEPSS 0.9%CVE-2018-3771—An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browseEPSS 0.9%CVE-2021-32852MEDIUMcountly-server vulnerable to Cross-site ScriptingEPSS 0.9%CVE-2022-36108MEDIUMCross-Site Scripting in typo3/cms-coreEPSS 0.9%CVE-2018-3755—XSS in sexstatic <=0.6.2 causes HTML injection in directory name(s) leads to Stored XSS when malicious file is embed with <iframe> element uEPSS 0.9%CVE-2018-3773—There is a stored Cross-Site Scripting vulnerability in Open Graph meta properties read by the `metascrape` npm module <= 3.9.2.EPSS 0.9%CVE-2021-39136HIGHCross-site scripting vulnerability in file uploadEPSS 0.9%CVE-2024-39143MEDIUMA stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious propertEPSS 0.9%CVE-2017-6618—A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker tEPSS 0.9%CVE-2020-29444MEDIUMAffected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross SitEPSS 0.9%CVE-2026-45249MEDIUMApache ECharts: XSS in Lines series tooltip renderingEPSS 0.9%CVE-2017-12269—A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform a stored cross-siteEPSS 0.9%CVE-2021-41252HIGHCross-site scripting (XSS) from writer field content in the site frontendEPSS 0.9%