Falhas do tipo CWE-79

29.055 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2024-1256LOWJspxcms filter_text.do cross site scriptingEPSS 0.6%CVE-2026-42455HIGHLinkWarden: Stored XSS via Client-Side Archive Upload (Unsanitized HTML served from same origin)EPSS 0.6%CVE-2022-38147MEDIUMSilverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).EPSS 0.6%CVE-2024-34078MEDIUMhtml-sanitizer allows arbitrary HTML present after sanitization because of unicode normalizationEPSS 0.6%CVE-2023-42656MEDIUMMOVEit Transfer Reflected XSSEPSS 0.6%CVE-2024-34460MEDIUMThe Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)EPSS 0.6%CVE-2023-2155LOWSourceCodester Air Cargo Management System cross site scriptingEPSS 0.6%CVE-2024-4265MEDIUMMaster Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 - Contributor+ Stored Cross-Site ScriptingEPSS 0.6%CVE-2024-30927MEDIUMCross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-results.php componentEPSS 0.6%CVE-2026-44588CRITICALSiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSSEPSS 0.6%CVE-2023-0246LOWearclink ESPCMS Content cross site scriptingEPSS 0.6%CVE-2023-4840MEDIUMMapPress Maps for WordPress <= 2.88.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.6%CVE-2023-1254LOWSourceCodester Health Center Patient Record Management System birthing_print.php cross site scriptingEPSS 0.6%CVE-2023-33971MEDIUMFormcreator vulnerable to stored XSS from ##FULLFORM##EPSS 0.6%CVE-2026-44670CRITICALSiYuan: Stored XSS via Attribute View name to Electron renderer RCE in SiYuanEPSS 0.6%CVE-2024-28853LOWAmpache Stored XSSEPSS 0.6%CVE-2024-26071MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.6%CVE-2020-22327MEDIUMAn issue was discovered in HFish 0.5.1. When a payload is inserted where the name is entered, XSS code is triggered when the administrator vEPSS 0.6%CVE-2024-33724MEDIUMSOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.EPSS 0.6%CVE-2026-40873HIGHmailcow: dockerized vulnerable to stored XSS in Quarantine attachment filenamesEPSS 0.6%