Weaknesses of type CWE-79

28,635 results

Injeção de conteúdo não sanitizado (XSS)

Ocorre quando dados não confiáveis (entrada de usuário, parâmetros, APIs externas) são inseridos diretamente no HTML, JavaScript ou contexto de renderização sem validação ou escape. Um atacante injeta código malicioso que executa no navegador da vítima, roubando cookies, sessões ou realizando ações em seu nome.

Example

Uma página de busca que exibe o termo procurado sem escape: se o usuário buscar por '<script>alert("hackeado")</script>', esse código é executado no navegador de quem visualizar o resultado. Um atacante pode injetar um script que rouba o token de autenticação.

How to mitigate

Escape ou encode toda entrada antes de renderizá-la (use funções nativas como textContent em JS, template engines com auto-escape como Jinja2 ou escapeHtml). Implemente Content Security Policy (CSP) para restringir execução de scripts inline. Valide e sanitize entrada no servidor, nunca confie apenas em validação client-side.

CVE-2023-33132MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.9%CVE-2020-1607HIGHJunos OS: Cross-Site Scripting (XSS) in J-WebEPSS 0.9%CVE-2020-7354MEDIUMRapid7 Metasploit Pro Stored XSS in 'host' fieldEPSS 0.9%CVE-2020-7355MEDIUMRapid7 Metasploit Pro Stored XSS in 'notes' fieldEPSS 0.9%CVE-2024-24574MEDIUMphpMyFAQ vulnerable to stored XSS on attachments filenameEPSS 0.9%CVE-2021-25041—Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)EPSS 0.9%CVE-2026-33168LOWRails has a possible XSS vulnerability in its Action View tag helpersEPSS 0.9%CVE-2024-50859MEDIUMThe ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the conteEPSS 0.9%CVE-2026-22029HIGHReact Router vulnerable to XSS via Open RedirectsEPSS 0.9%CVE-2023-26773MEDIUMCross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the producEPSS 0.9%CVE-2023-4771MEDIUMCross-Site Scripting vulnerability in CKSource CKEditorEPSS 0.9%CVE-2018-16861HIGHA cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the HoEPSS 0.9%CVE-2024-27132HIGHInsufficient sanitization in MLflow leads to XSS when running an untrusted recipe.EPSS 0.9%CVE-2018-6588—CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.EPSS 0.9%CVE-2018-6586—CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processinEPSS 0.9%CVE-2021-4139MEDIUMCross-site Scripting (XSS) - Stored in pimcore/pimcoreEPSS 0.9%CVE-2024-0286MEDIUMPHPGurukul Hospital Management System Contact Form index.php#contact_us cross site scriptingEPSS 0.9%CVE-2018-6587—CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.EPSS 0.9%CVE-2022-0601—Countdown & Clock < 2.2.9 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25027—PowerPack Addons for Elementor < 2.6.2 - Reflected Cross-Site ScriptingEPSS 0.9%