Falhas do tipo CWE-79

28.947 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2022-30003MEDIUMSourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then creEPSS 0.6%CVE-2022-39054MEDIUMCOWELL INFORMATION SYSTEM CO., LTD. enterprise travel management system - Reflected XSSEPSS 0.6%CVE-2022-39035MEDIUMSmart eVision - Stored XSSEPSS 0.6%CVE-2022-4029MEDIUMSimple:Press <= 6.8 - Reflected Cross-Site Scripting via Cookie ValueEPSS 0.6%CVE-2026-12496HIGHLoytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA serverEPSS 0.6%CVE-2024-34707HIGHNautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pagesEPSS 0.6%CVE-2024-50346MEDIUMWebFeed HTML injection vulnerabilitiesEPSS 0.6%CVE-2026-45738HIGHArgo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalationEPSS 0.6%CVE-2018-16484—A XSS vulnerability was found in module m-server <1.4.2 that allows malicious Javascript code or HTML to be executed, due to the lack of escEPSS 0.6%CVE-2026-55730HIGHLoytec LWEB802: Reflected Cross-Site Scripting in LWEB802EPSS 0.6%CVE-2022-39053MEDIUMHEIMAVISTA INC. Rpage - Reflected XSSEPSS 0.6%CVE-2023-48986MEDIUMCross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attackerEPSS 0.6%CVE-2024-3695LOWSourceCodester Computer Laboratory Management System Users.php cross site scriptingEPSS 0.6%CVE-2017-20153LOWaerouk imageserve cross site scriptingEPSS 0.6%CVE-2023-3158HIGHMail Control <= 0.2.8 - Unauthenticated Stored Cross-Site Scripting via Email SubjectEPSS 0.6%CVE-2023-3783LOWWebile HTTP POST Request cross site scriptingEPSS 0.6%CVE-2023-2388LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%CVE-2023-28639MEDIUMGLPI vulnerable to reflected Cross-site Scripting in search pagesEPSS 0.6%CVE-2023-6303LOWCSZCMS Site Settings Page cross site scriptingEPSS 0.6%CVE-2023-2387LOWNetgear SRX5308 Web Management Interface cross site scriptingEPSS 0.6%