Weaknesses of type CWE-79

28,628 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2021-23038—On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stoEPSS 0.9%CVE-2020-8120—A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.EPSS 0.9%CVE-2021-39328MEDIUMSimple Job Board <= 2.9.4 Authenticated Stored Cross-Site ScriptingEPSS 0.9%CVE-2021-39357MEDIUMLeaky Paywall <= 4.16.5 Authenticated Stored Cross-Site ScriptingEPSS 0.9%CVE-2022-0719HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 0.9%CVE-2026-51133MEDIUMCross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary codEPSS 0.9%CVE-2015-20019—Content text slider on post < 6.9 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%CVE-2021-41086HIGHClipboard-based XSS in jsuitesEPSS 0.9%CVE-2022-44948MEDIUMRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?moEPSS 0.9%CVE-2022-27878MEDIUMOn all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions priEPSS 0.9%CVE-2018-18997—Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrativEPSS 0.9%CVE-2021-43861HIGHIncorrect sanitisation function leads to `XSS`EPSS 0.9%CVE-2017-20008—myCRED < 1.7.8 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2007-1679MEDIUMMultiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web EPSS 0.9%CVE-2018-0367—A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attackerEPSS 0.9%CVE-2022-26105—SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unautheEPSS 0.9%CVE-2020-27832—A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notificaEPSS 0.9%CVE-2018-15634HIGHCross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows reEPSS 0.9%CVE-2024-11587MEDIUMidcCMS classProvCity.php GetCityOptionJs cross site scriptingEPSS 0.9%CVE-2019-1719MEDIUMCisco Identity Services Engine Cross-Site Scripting VulnerabilityEPSS 0.9%