Falhas do tipo CWE-79

29.274 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2024-32409HIGHAn issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.EPSS 0.5%CVE-2026-11982MEDIUMStored XSS via missing XSS safety check in Admin2 Pages API partial validationEPSS 0.5%CVE-2022-41980MEDIUMWordPress Mantenimiento web plugin <= 0.13 - Auth. Cross-Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2026-62829MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.5%CVE-2024-42515CRITICALGlossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <EPSS 0.5%CVE-2025-68669CRITICAL5ire vulnerable to Remote Code Execution (RCE) via mermaidEPSS 0.5%CVE-2024-22776MEDIUMWallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring sEPSS 0.5%CVE-2026-63671HIGH@nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configurationEPSS 0.5%CVE-2026-78615MEDIUMWatchGuard Dimension Reflected DOM-Based XSS in Report Detail PageEPSS 0.5%CVE-2024-23172MEDIUMAn issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.EPSS 0.5%CVE-2024-13034MEDIUMcode-projects Chat System update_user.php cross site scriptingEPSS 0.5%CVE-2022-39027MEDIUMe-Excellence Inc. U-Office Force - Stored XSSEPSS 0.5%CVE-2025-2714MEDIUMJoomlaUX JUX Real Estate addagent cross site scriptingEPSS 0.5%CVE-2026-77830HIGHSpam protection, Honeypot, Anti-Spam by CleanTalk <= 6.86 - Unauthenticated Stored Cross-Site Scripting via Comment Content aria-label PlaceholderEPSS 0.5%CVE-2024-37629MEDIUMSummerNote v0.9.1 is vulnerable to Cross Site Scripting (XSS) via the Code View Function.EPSS 0.5%CVE-2024-27902MEDIUMCross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS ABAP applications based on SAPGUI for HTML (WebGUI)EPSS 0.5%CVE-2026-82535MEDIUMChamilo LMS Stored XSS via Survey Answer Submission in reporting.phpEPSS 0.5%CVE-2022-39026MEDIUMe-Excellence Inc. U-Office Force - Stored XSSEPSS 0.5%CVE-2023-45207MEDIUMAn issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. An attacker can send a PDF document through mail that contains EPSS 0.5%CVE-2026-42849CRITICALauthentik: Reflected XSS in SFE AutosubmitStage allows IDP account takeoverEPSS 0.5%