Falhas do tipo CWE-79

28.759 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2023-25825HIGHZoneMinder contains Cross-site Scripting via log viewingEPSS 0.7%CVE-2025-55143MEDIUMReflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway beforeEPSS 0.7%CVE-2024-22411MEDIUMCross site scripting in Action messages on AvoEPSS 0.7%CVE-2018-15641MEDIUMCross-site scripting (XSS) issue in web module in Odoo Community 11.0 through 14.0 and Odoo Enterprise 11.0 through 14.0, allows remote authEPSS 0.7%CVE-2019-5458—Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execEPSS 0.7%CVE-2022-2028HIGHCross-site Scripting (XSS) - Generic in kromitgmbh/titraEPSS 0.7%CVE-2022-2026HIGHCross-site Scripting (XSS) - Stored in kromitgmbh/titraEPSS 0.7%CVE-2021-32857MEDIUMCockpit vulnerable to Cross-site ScriptingEPSS 0.7%CVE-2019-5457—Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execuEPSS 0.7%CVE-2022-38106MEDIUMCross-Site Scripting Vulnerability in Serv-U Web ClientEPSS 0.7%CVE-2022-31038MEDIUMXSS vulnerability in repository issue list in GogsEPSS 0.7%CVE-2022-2029HIGHCross-site Scripting (XSS) - DOM in kromitgmbh/titraEPSS 0.7%CVE-2022-22124MEDIUMHalo CMS - Stored Cross-Site Scripting (XSS) in Profile ImageEPSS 0.7%CVE-2021-41101MEDIUMCORS `Access-Control-Allow-Origin` settings are too lenientEPSS 0.7%CVE-2024-38503LOWApache Syncope: HTML tags can be injected into Console or Enduser text fieldsEPSS 0.7%CVE-2023-26149MEDIUMVersions of the package quill-mention before 4.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper user-input sanitization, viaEPSS 0.7%CVE-2022-2861MEDIUMInappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install EPSS 0.7%CVE-2021-28161—In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injEPSS 0.7%CVE-2022-24386HIGHStored XSS in SmarterTrack v100.0.8019.14010EPSS 0.7%CVE-2022-22123MEDIUMHalo CMS - Stored Cross-Site Scripting (XSS) in Article's TitleEPSS 0.7%