Falhas do tipo CWE-79

28.677 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2023-20085MEDIUMA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 0.7%CVE-2019-10180LOWA vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parametEPSS 0.7%CVE-2026-73415HIGHjupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tabEPSS 0.7%CVE-2023-51504MEDIUMWordPress Dan's Embedder for Google Calendar Plugin <= 1.2 is vulnerable to Cross Site Scripting (XSS)EPSS 0.7%CVE-2023-34089HIGHDecidim Cross-site Scripting vulnerability in the processes filterEPSS 0.7%CVE-2024-52762MEDIUMA cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbEPSS 0.7%CVE-2021-37710HIGHCross-Site Scripting via SVG media filesEPSS 0.7%CVE-2021-39169HIGHXSS vulnerability using dialogEPSS 0.7%CVE-2022-0956HIGHStored XSS via File Upload in star7th/showdocEPSS 0.7%CVE-2025-48954HIGHDiscourse vulnerable to XSS via user-provided query parameter in oauth failure flowEPSS 0.7%CVE-2021-32713MEDIUMAuthenticated Stored XSSEPSS 0.7%CVE-2022-42225MEDIUMJumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of user input, which can eEPSS 0.7%CVE-2026-53963HIGHDiscourse: Stored-XSS in 2FA delete confirmation modalEPSS 0.7%CVE-2022-43569HIGHPersistent Cross-Site Scripting via a Data Model object name in Splunk EnterpriseEPSS 0.7%CVE-2021-24152—Popup Builder < 3.74 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2022-22182HIGHJunos OS: A XSS vulnerability allows an attacker to execute commands on a target J-Web sessionEPSS 0.7%CVE-2022-1291HIGHXSS vulnerability with default `onCellHtmlData` function in hhurz/tableexport.jquery.pluginEPSS 0.7%CVE-2024-24570HIGHStatamic account takeover via XSS and password reset linkEPSS 0.7%CVE-2024-11387MEDIUMEasy Liveblogs <= 2.3.5 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-40190HIGHSAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web application does not adequateEPSS 0.7%