Falhas do tipo CWE-79

29.160 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2024-1956MEDIUMWPB Show Core < 2.7 - Reflected XSSEPSS 0.5%CVE-2024-23191MEDIUMUpsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To expEPSS 0.5%CVE-2024-2259MEDIUMReflected XXS Vulnerability in InstaRISPACS SoftwareEPSS 0.5%CVE-2023-46744MEDIUMStored Cross-site Scripting in SquidexEPSS 0.5%CVE-2024-23895HIGHCross-Site Scripting (XSS) vulnerability in Cups EasyEPSS 0.5%CVE-2024-43737MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2024-43718MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2025-51990MEDIUMXWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specEPSS 0.5%CVE-2024-47925HIGHTecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')EPSS 0.5%CVE-2017-5256—In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System DeEPSS 0.5%CVE-2026-25616MEDIUMBlesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.EPSS 0.5%CVE-2024-40631HIGHCross-site Scripting (XSS) in media embed element when using custom URL parsers in plate mediaEPSS 0.5%CVE-2024-37384MEDIUMRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.EPSS 0.5%CVE-2026-66494HIGHJoomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0EPSS 0.5%CVE-2024-53481MEDIUMA Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers toEPSS 0.5%CVE-2024-51486MEDIUMStored Cross-Site Scripting in AmpacheEPSS 0.5%CVE-2023-0110HIGHCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.5%CVE-2023-0107MEDIUMCross-site Scripting (XSS) - Stored in usememos/memosEPSS 0.5%CVE-2026-78438HIGHW3 Total Cache <= 2.10.5 - Unauthenticated Stored Cross-Site Scripting via LazyLoad Background MutatorEPSS 0.5%CVE-2023-0949MEDIUMCross-site Scripting (XSS) - Reflected in modoboa/modoboaEPSS 0.5%