Falhas do tipo CWE-79

28.666 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2025-50128CRITICALA cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev masteEPSS 0.8%CVE-2021-29116MEDIUMBUG-000142180 Hosted feature services vulnerable to stored XSSEPSS 0.8%CVE-2026-70355HIGHMicrosoft SharePoint Server Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-46410CRITICALA cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 aEPSS 0.8%CVE-2022-1951—Core Plugin for Kitestudio Themes < 2.3.1 - Reflected Cross-Site-ScriptingEPSS 0.8%CVE-2024-29890HIGHRemote code execution in datalens-uiEPSS 0.8%CVE-2019-15614—Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files.EPSS 0.8%CVE-2021-24873—Tutor LMS < 1.9.11 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2021-38357MEDIUMSMS OVH <= 0.1 Reflected Cross-Site ScriptingEPSS 0.8%CVE-2021-24908—Check & Log Email < 1.0.4 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2024-45595MEDIUMD-Tale allows Remote Code Execution through the Query input on Chart BuilderEPSS 0.8%CVE-2022-0877HIGHCross-site Scripting (XSS) - Stored in bookstackapp/bookstackEPSS 0.8%CVE-2020-11055MEDIUMCross-site Scripting in BookStackEPSS 0.8%CVE-2021-38358MEDIUMMoolaMojo <= 0.7.4.1 Reflected Cross-Site ScriptingEPSS 0.8%CVE-2021-4107MEDIUMCross-site Scripting (XSS) - Reflected in yetiforcecompany/yetiforcecrmEPSS 0.8%CVE-2022-42715MEDIUMA reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uEPSS 0.8%CVE-2024-40509HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmEPSS 0.8%CVE-2026-9086HIGHKeycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypassEPSS 0.8%CVE-2024-40785MEDIUMThis issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, mEPSS 0.8%CVE-2025-1359MEDIUMSIAM Industria de Automação e Monitoramento qrcode.jsp cross site scriptingEPSS 0.8%