Falhas do tipo CWE-79

28.827 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2021-24330—Funnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google Analytics IDEPSS 0.7%CVE-2022-4840HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.7%CVE-2020-15083MEDIUMReflected XSS when uploading an image in the Product page in PrestaShopEPSS 0.7%CVE-2021-24331—Smooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSSEPSS 0.7%CVE-2023-32070CRITICALImproper Neutralization of Script in Attributes in XWiki (X)HTML renderersEPSS 0.7%CVE-2021-45071MEDIUMCross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbEPSS 0.7%CVE-2022-4695HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.7%CVE-2024-55074HIGHThe edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG filEPSS 0.7%CVE-2022-1530LOWCross-site Scripting (XSS) in livehelperchat/livehelperchatEPSS 0.7%CVE-2025-25304MEDIUMVega allows Cross-site Scripting via the vlSelectionTuples functionEPSS 0.7%CVE-2022-31889MEDIUMCross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533EPSS 0.7%CVE-2024-9414HIGHCross-site Scripting vulnerability in LCDS LAquis SCADAEPSS 0.7%CVE-2023-33195MEDIUMCraft CMS XSS in RSS widget feedEPSS 0.7%CVE-2026-39846CRITICALSiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced table captionsEPSS 0.7%CVE-2024-37304MEDIUMNuGetGallery's Markdown Autolinks Processing Vulnerable to Cross-site ScriptingEPSS 0.7%CVE-2022-23458MEDIUMToast UI Grid vulnerable to Cross-site scriptingEPSS 0.7%CVE-2026-33067MEDIUMSiYuan has Stored XSS to RCE via Unsanitized Bazaar Package MetadataEPSS 0.7%CVE-2024-0611MEDIUMMaster Slider – Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callbackEPSS 0.7%CVE-2021-24682—Cool Tag Cloud < 2.26 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24672—One User Avatar < 2.3.7 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%