Falhas do tipo CWE-79

29.081 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2022-20632MEDIUMCisco Enterprise Chat and Email Cross-Site Scripting VulnerabilityEPSS 0.5%CVE-2022-39375MEDIUMCross-Site Scripting (XSS) through public RSS feed in GLPIEPSS 0.5%CVE-2026-15217HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2023-5665MEDIUMPayment Forms for Paystack <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2025-27654MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Cross Site Scripting (XSS) V-2023-0EPSS 0.5%CVE-2025-27653MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Preauthenticated Cross Site ScriptiEPSS 0.5%CVE-2026-84370HIGHSVGO: removeScripts allows executable links through namespace and control-character bypassesEPSS 0.5%CVE-2026-82089HIGHThe wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a EPSS 0.5%CVE-2026-15216HIGHImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabEPSS 0.5%CVE-2021-39332MEDIUMBusiness Manager – WordPress ERP, HR, CRM, and Project Management Plugin <= 1.4.5 Authenticated Stored Cross-Site ScriptingEPSS 0.5%CVE-2025-27637MEDIUMVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Cross-Site Scripting V-2024-016.EPSS 0.5%CVE-2022-35297—The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being EPSS 0.5%CVE-2024-45613MEDIUMCKEditor 5 has Cross-site Scripting vulnerability in the clipboard packageEPSS 0.5%CVE-2020-35698MEDIUMThinkific Thinkific Online Course Creation Platform 1.0 is affected by: Cross Site Scripting (XSS). The impact is: execute arbitrary code (rEPSS 0.5%CVE-2022-42348MEDIUMAEM Reflected XSS Arbitrary code executionEPSS 0.5%CVE-2022-4413MEDIUMCross-site Scripting (XSS) - Reflected in nuxt/frameworkEPSS 0.5%CVE-2019-25092LOWNakiami Mellivora Admin Panel user.inc.php print_user_ip_log cross site scriptingEPSS 0.5%CVE-2023-53155HIGHgoform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.EPSS 0.5%CVE-2025-66562HIGHTUUI vulnerable to Remote Code Execution (RCE) via XSS in Markdown ECharts RenderingEPSS 0.5%CVE-2022-43120MEDIUMA cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows attackers to execute EPSS 0.5%