Falhas do tipo CWE-79

29.271 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2023-51281MEDIUMCross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firEPSS 0.5%CVE-2024-7247MEDIUMElement Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown WidgetsEPSS 0.5%CVE-2024-45123MEDIUMAdobe Commerce | Cross-site Scripting (Reflected XSS) (CWE-79)EPSS 0.5%CVE-2021-36206CRITICALCEVASEPSS 0.5%CVE-2025-25187HIGHCross-site Scripting in Goto Anything allows arbitrary code execution in JoplinEPSS 0.5%CVE-2026-31845CRITICALRukovoditel CRM Reflected XSS via zd_echo Parameter in Zadarma Telephony API EndpointEPSS 0.5%CVE-2022-4712HIGHWP Cerber Security <= 9.1 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-5049MEDIUMGiveaways and Contests by RafflePress <= 1.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.5%CVE-2023-44301MEDIUM Dell DM5500 5.14.0.0 and prior contain a Reflected Cross-Site Scripting Vulnerability. A network attacker with low privileges could potenEPSS 0.5%CVE-2026-3070MEDIUMSourceCodester Modern Image Gallery App upload.php cross site scriptingEPSS 0.5%CVE-2025-27205MEDIUMAdobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)EPSS 0.5%CVE-2026-3412MEDIUMitsourcecode University Management System att_single_view.php cross site scriptingEPSS 0.5%CVE-2024-11377MEDIUMAutomate Hub Free by Sperse.IO <= 1.7.0 - Reflected Cross-Site ScriptingEPSS 0.5%CVE-2026-3043MEDIUMitsourcecode Event Management System navbar.php cross site scriptingEPSS 0.5%CVE-2024-5711HIGHStored XSS in stitionai/devikaEPSS 0.5%CVE-2023-2740LOWSourceCodester Guest Management System GET Parameter dateTest.php cross site scriptingEPSS 0.5%CVE-2023-27776MEDIUMA stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows attackers to execute aEPSS 0.5%CVE-2022-47415MEDIUMLogicalDOC Messaging Stored XSSEPSS 0.5%CVE-2014-125108LOWw3c online-spellchecker-py spellchecker cross site scriptingEPSS 0.5%CVE-2026-3812MEDIUMitsourcecode Payroll Management System manage_employee_allowances.php cross site scriptingEPSS 0.5%