Falhas do tipo CWE-79

29.081 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2024-49593MEDIUMIn Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor tEPSS 0.5%CVE-2022-40712MEDIUMAn issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.EPSS 0.5%CVE-2023-7075LOWcode-projects Point of Sales and Inventory Management System checkout.php cross site scriptingEPSS 0.5%CVE-2022-25276MEDIUMThe Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed in the context of thEPSS 0.5%CVE-2022-34315MEDIUMIBM CICS TX cross-site scriptingEPSS 0.5%CVE-2023-1243MEDIUMCross-site Scripting (XSS) - Stored in answerdev/answerEPSS 0.5%CVE-2024-44085MEDIUMONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoEPSS 0.5%CVE-2023-1239MEDIUMCross-site Scripting (XSS) - Reflected in answerdev/answerEPSS 0.5%CVE-2024-7874MEDIUMXSS in Tungsten Automation TotalAgilityEPSS 0.5%CVE-2017-7534—OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user inEPSS 0.5%CVE-2024-11246MEDIUMcode-projects Farmacia adicionar-cliente.php cross site scriptingEPSS 0.5%CVE-2025-27637MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016.EPSS 0.5%CVE-2025-24853HIGHApache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processingEPSS 0.5%CVE-2022-39375MEDIUMCross-Site Scripting (XSS) through public RSS feed in GLPIEPSS 0.5%CVE-2024-0449MEDIUMArtiBot Free Chat Bot for WordPress WebSites <= 1.1.6 - Authenticated (Admin+) Cross-Site ScriptingEPSS 0.5%CVE-2022-36137MEDIUMChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.EPSS 0.5%CVE-2023-33548MEDIUMCross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to ruEPSS 0.5%CVE-2023-23627MEDIUMSanitize vulnerable to Cross-site Scripting via Improper neutralization of `noscript` elementEPSS 0.5%CVE-2026-15217HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2026-40598MEDIUMMantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update PageEPSS 0.5%