Falhas do tipo CWE-79

28.772 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2023-36809HIGHKiwi TCMS's misconfigured HTTP headers allow stored XSS execution with FirefoxEPSS 0.7%CVE-2022-24709HIGHCross site scripting in @awsui/components-reactEPSS 0.7%CVE-2022-4271HIGHCross-site Scripting (XSS) - Reflected in osticket/osticketEPSS 0.7%CVE-2025-41393MEDIUMReflected cross-site scripting vulnerability exists in the laser printers and MFPs (multifunction printers) which implement Ricoh Web Image EPSS 0.7%CVE-2026-4313LOWStored XSS in AdaptiveGRCEPSS 0.7%CVE-2018-16481—A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absEPSS 0.7%CVE-2023-26131MEDIUMAll versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerablEPSS 0.7%CVE-2021-24225—Advanced Booking Calendar < 1.6.7 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2024-27300MEDIUMphpMyFAQ Stored XSS at user emailEPSS 0.7%CVE-2023-4979HIGHCross-site Scripting (XSS) - Reflected in librenms/librenmsEPSS 0.7%CVE-2023-0549LOWYAFNET Private Message PostPrivateMessage cross site scriptingEPSS 0.7%CVE-2024-7644MEDIUMSourceCodester Leads Manager Tool Add Leads add-leads.php cross site scriptingEPSS 0.7%CVE-2021-27436—WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code EPSS 0.7%CVE-2023-4980HIGHCross-site Scripting (XSS) - Generic in librenms/librenmsEPSS 0.7%CVE-2021-34361MEDIUMReflected XSS Vulnerability in Proxy ServerEPSS 0.7%CVE-2021-38680MEDIUMReflected XSS in Kazoo ServerEPSS 0.7%CVE-2023-5485MEDIUMInappropriate implementation in Autofill in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to bypass autofill restrictions vEPSS 0.7%CVE-2024-44088MEDIUMApache Geode: Reflected XSSEPSS 0.7%CVE-2024-3542LOWCampcodes Church Management System add_visitor.php cross site scriptingEPSS 0.7%CVE-2021-29106MEDIUMThere is a reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below.EPSS 0.7%