Weaknesses of type CWE-79

28,626 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2018-0450—Cisco Data Center Network Manager Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-43170MEDIUMA stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of RukEPSS 0.9%CVE-2018-15400—Cisco Cloud Services Platform 2100 Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-43166MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) of Rukovoditel v3.2.1EPSS 0.9%CVE-2018-15434—Cisco Unified IP Phone 7900 Series Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2026-22813CRITICALMalicious website can execute commands on the local system through XSS in the OpenCode web UIEPSS 0.9%CVE-2022-43169MEDIUMA stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/users_groups) of RukovoEPSS 0.9%CVE-2022-43165MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) of Rukovoditel v3.2.1EPSS 0.9%CVE-2022-43164MEDIUMA stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of Rukovoditel v3.2.1 aEPSS 0.9%CVE-2018-0452—Cisco Tetration Analytics Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2019-1655MEDIUMCisco Webex Meetings Server Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2018-19954—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2019-9509MEDIUMThe web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected cross site scriptingEPSS 0.9%CVE-2018-19956—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2021-24976—Smart SEO Tool < 3.0.6 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2018-19955—The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could EPSS 0.9%CVE-2023-2587HIGH Teltonika’s Remote Management System versions prior to 4.10.0 contain a cross-site scripting (XSS) vulnerability in the main page of the weEPSS 0.9%CVE-2018-16468—In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.EPSS 0.9%CVE-2023-39513MEDIUMStored Cross-site Scripting on host.php verbose data-query debug view in CactiEPSS 0.9%CVE-2021-23038—On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stoEPSS 0.9%