Falhas do tipo CWE-79

28.767 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2021-21398MEDIUMPossible XSS injection through DataColumn Grid classEPSS 0.7%CVE-2024-43744MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-43749MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-43734MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-43747MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2024-43743MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%CVE-2022-41239MEDIUMJenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying theEPSS 0.7%CVE-2023-48701HIGHStatamic CMS vulnerable to Cross-site Scripting via uploaded assetsEPSS 0.7%CVE-2026-56397CRITICALSiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and READMEEPSS 0.7%CVE-2021-3529—A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML docuEPSS 0.7%CVE-2021-42365MEDIUMAsgaros Forums <= 1.15.13 Authenticated Stored XSSEPSS 0.7%CVE-2022-2342HIGHCross-site Scripting (XSS) - Stored in outline/outlineEPSS 0.7%CVE-2022-45408MEDIUMThrough a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification pEPSS 0.7%CVE-2022-0375MEDIUMCross-site Scripting (XSS) - Stored in livehelperchat/livehelperchatEPSS 0.7%CVE-2021-32818HIGHRemote code execution and Reflected cross site scripting in haml-coffeeEPSS 0.7%CVE-2018-14520MEDIUMAn issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web EPSS 0.7%CVE-2021-25026—Patreon WordPress < 1.8.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-25761MEDIUMJenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored EPSS 0.7%CVE-2015-20106—ClickBank Affiliate Ads <= 1.20 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2026-34686HIGHAdobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.7%