Weaknesses of type CWE-79

28,634 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2020-36635LOWOpenMRS Appointment Scheduling Module AppointmentTypeValidator.java validateFieldName cross site scriptingEPSS 0.9%CVE-2019-13943—A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versiEPSS 0.9%CVE-2021-25062—Orders Tracking for WooCommerce < 1.1.10 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2024-23645MEDIUMGLPI reflected XSS in reports pagesEPSS 0.9%CVE-2016-5819—Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflecEPSS 0.9%CVE-2015-9102—Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote autheEPSS 0.9%CVE-2022-2826LOWAn issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.1EPSS 0.9%CVE-2020-26225HIGHReflected XSS in PrestaShop Product CommentsEPSS 0.9%CVE-2021-21319MEDIUMSeveral stored XSSEPSS 0.9%CVE-2022-42989CRITICALERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.EPSS 0.9%CVE-2018-3780—A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-intEPSS 0.9%CVE-2018-0276—A vulnerability in Cisco WebEx Connect IM could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack agaEPSS 0.9%CVE-2024-57514MEDIUMThe TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web EPSS 0.9%CVE-2019-1733MEDIUMCisco NX-OS Software NX-API Sandbox Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2022-40956MEDIUMWhen injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. EPSS 0.9%CVE-2024-30875HIGHCross Site Scripting vulnerability in JavaScript Library jquery-ui v.1.13.1 allows a remote attacker to obtain sensitive information and exeEPSS 0.9%CVE-2021-34653MEDIUMWP Fountain <= 1.5.9 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2015-10073LOWtinymighty WikiSEO Meta Property Tag WikiSEO.body.php modifyHTML cross site scriptingEPSS 0.9%CVE-2023-29712MEDIUMCross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to EPSS 0.9%CVE-2021-24720—GeoDirectory < 2.1.1.3 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%