Falhas do tipo CWE-79

28.669 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2025-51501MEDIUMReflected Cross-Site Scripting (XSS) in the id parameter of the live_edit.module_settings API endpoint in Microweber CMS2.0 allows executionEPSS 0.8%CVE-2022-1988MEDIUMCross-site Scripting (XSS) - Generic in neorazorx/facturascriptsEPSS 0.8%CVE-2021-36875MEDIUMWordPress uListing plugin <= 2.0.5 - Auth. Reflected Cross-Site Scripting (XSS) vulnerabilityEPSS 0.8%CVE-2021-3646MEDIUMCross-site Scripting (XSS) - Reflected in btcpayserver/btcpayserverEPSS 0.8%CVE-2025-25001MEDIUMMicrosoft Edge for iOS Spoofing VulnerabilityEPSS 0.8%CVE-2018-16480—A XSS vulnerability was found in module public <0.1.4 that allows malicious Javascript code to run in the browser, due to the absence of sanEPSS 0.8%CVE-2024-42852MEDIUMCross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary code via the index.php EPSS 0.8%CVE-2022-2532—Feed Them Social < 3.0.1 - Reflected Cross-Site ScriptingEPSS 0.8%CVE-2024-42346HIGHStored Cross Site Scripting (Stored XSS) in GalaxyEPSS 0.8%CVE-2022-31192HIGHCross Site Scripting possible in DSpace JSPUI "Request a Copy" featureEPSS 0.8%CVE-2024-39031MEDIUMIn Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite othEPSS 0.8%CVE-2024-56527HIGHAn issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.EPSS 0.8%CVE-2020-10041—A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A stored EPSS 0.8%CVE-2022-40088MEDIUMSimple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /college_websitEPSS 0.8%CVE-2019-25140HIGHComing Soon Page & Maintenance Mode <= 1.8.1 - Stored Cross Site ScriptingEPSS 0.8%CVE-2022-0957HIGHStored XSS via File Upload in star7th/showdocEPSS 0.8%CVE-2022-4839HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.8%CVE-2022-0370HIGHCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchatEPSS 0.8%CVE-2022-1514CRITICALStored XSS via upload plugin functionality in zip format in neorazorx/facturascriptsEPSS 0.8%CVE-2020-2493—Cross-site Scripting Vulnerability in Multimedia ConsoleEPSS 0.8%