Falhas do tipo CWE-79

28.949 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2025-30223CRITICALBeego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User InputEPSS 0.6%CVE-2021-21442MEDIUMXSS vulnerability in Time AccountingEPSS 0.6%CVE-2024-2081MEDIUMFooGallery <= 2.4.14 - Authenticated (Author+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-29105MEDIUMThere is a stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below.EPSS 0.6%CVE-2023-2298HIGHOnline Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-42486MEDIUMStored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote authenticated attackeEPSS 0.6%CVE-2026-49995MEDIUMTautulli: Stored Cross-Site Scripting (XSS) in the newsletterEPSS 0.6%CVE-2022-46087MEDIUMCloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notificatEPSS 0.6%CVE-2024-8017CRITICALCross-site Scripting (XSS) in open-webui/open-webuiEPSS 0.6%CVE-2022-1840LOWHome Clean Services Management System cross site scriptingEPSS 0.6%CVE-2024-0826MEDIUMQi Addons For Elementor <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2023-25763MEDIUMJenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored crEPSS 0.6%CVE-2024-4036MEDIUMSydney Toolbox <= 1.30 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-15401HIGHVikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' ParameterEPSS 0.6%CVE-2024-4156MEDIUMEssential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.6%CVE-2021-25986MEDIUMDjango-wiki - Stored Cross-Site Scripting (XSS) in Notifications SectionEPSS 0.6%CVE-2024-11370MEDIUMSubaccounts for WooCommerce <= 1.6.0 - Reflected Cross-Site ScriptingEPSS 0.6%CVE-2022-0209MEDIUMMitsol Social Post Feed < 1.11 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2026-34605HIGHSiYuan: Reflected XSS via SVG namespace prefix bypass in SanitizeSVG ( getDynamicIcon, unauthenticated )EPSS 0.6%CVE-2023-25764MEDIUMJenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generatedEPSS 0.6%