Falhas do tipo CWE-79

28.973 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2023-27592MEDIUMStored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handlerEPSS 0.6%CVE-2014-125103LOWBestWebSoft Twitter Plugin twitter.php twttr_settings_page cross site scriptingEPSS 0.6%CVE-2021-42329MEDIUMShinHer Information Co., LTD. ShinHer StudyOnline System - Stored XSSEPSS 0.6%CVE-2021-30170MEDIUMJun-He Technology Ltd. ERP POS - Stored XSS-1EPSS 0.6%CVE-2024-34355LOWTYPO3 vulnerable to an HTML Injection in the History ModuleEPSS 0.6%CVE-2021-33231MEDIUMCross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote attackers to run arbiEPSS 0.6%CVE-2021-30172MEDIUMJun-He Technology Ltd. Quan-Fang-Wei-Tong-Xun system - Reflected XSSEPSS 0.6%CVE-2023-32977MEDIUMJenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a storedEPSS 0.6%CVE-2021-42335MEDIUMHuachu Digital Technology Co.,Ltd. Easytest - Stored XSSEPSS 0.6%CVE-2021-32539MEDIUMHundred Plus 101EIP - Stored XSS-1EPSS 0.6%CVE-2021-32544MEDIUMIntelligent global technology Ltd, igt+ - DOM-based Cross-Site ScriptingEPSS 0.6%CVE-2021-30171MEDIUMJun-He Technology Ltd. ERP POS - Stored XSS-2EPSS 0.6%CVE-2021-3834MEDIUMIntegria IMS vulnerable to Cross Site Scripting (XSS)EPSS 0.6%CVE-2023-25292MEDIUMReflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain seEPSS 0.6%CVE-2022-1028—WordPress Security < 4.2.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2022-1995—miniOrange's Malware Scanner < 4.5.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2025-25427HIGHXSS in TP-Link TL-WR841N v14/v14.6/v14.8 Upnp pageEPSS 0.6%CVE-2023-4707LOWInfosoftbd Clcknshop all cross site scriptingEPSS 0.6%CVE-2021-36870MEDIUMWordPress WP Google Maps plugin <= 8.1.12 - Multiple Authenticated Persistent XSS vulnerabilitiesEPSS 0.6%CVE-2023-0829HIGHCross-Site Scripting (XSS) vulnerability in PleskEPSS 0.6%