Falhas do tipo CWE-79

28.691 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2017-6511MEDIUMandrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in appEPSS 0.7%CVE-2024-44778HIGHA reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execuEPSS 0.7%CVE-2022-22229HIGHParagon Active Assurance (Formerly Netrounds): Stored Cross-site Scripting (XSS) vulnerability in web administrationEPSS 0.7%CVE-2024-27838MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17EPSS 0.7%CVE-2024-40506HIGHCross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitalitEPSS 0.7%CVE-2022-22748MEDIUMMalicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL prEPSS 0.7%CVE-2022-2589MEDIUMCross-site Scripting (XSS) - Reflected in beancount/favaEPSS 0.7%CVE-2024-2692CRITICALSiYuan 3.0.3 - RCE via Server Side XSSEPSS 0.7%CVE-2019-15618—Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.EPSS 0.7%CVE-2022-1938—Awin Data Feed < 1.8 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-42547MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Out-of-the-BoxEPSS 0.7%CVE-2021-42549MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Lets-BoxEPSS 0.7%CVE-2021-42548MEDIUMreflected XSS in search functionality of WP Cloud Plugins - Share-one-DriveEPSS 0.7%CVE-2021-42546MEDIUMReflected XSS in search functionality of WP Cloud Plugins - Use-Your-DriveEPSS 0.7%CVE-2026-32626CRITICALAnythingLLM has a Streaming Phase XSS to RCE via LLM Response InjectionEPSS 0.7%CVE-2026-88057MEDIUMAngular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compilerEPSS 0.7%CVE-2021-24794—Connections Business Directory < 10.4.3 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-28599MEDIUMZoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentiaEPSS 0.7%CVE-2025-47110HIGHAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2022-4710MEDIUMRoyal Elementor Addons <= 1.3.59 - Reflected Cross-Site ScriptingEPSS 0.7%