Falhas do tipo CWE-79

28.443 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2025-51403MEDIUMA stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers EPSS 1.5%CVE-2017-6762—A vulnerability in the web-based management interface of Cisco Jabber Guest Server 10.6(9), 11.0(0), and 11.0(1) could allow an unauthenticaEPSS 1.5%CVE-2017-6761—A vulnerability in the web-based management interface of Cisco Finesse 10.6(1) and 11.5(1) could allow an unauthenticated, remote attacker tEPSS 1.5%CVE-2023-27008MEDIUMA Cross-site scripting (XSS) vulnerability in the function encrypt_password() in login.tmpl.php in ATutor 2.2.1 allows remote attackers to iEPSS 1.5%CVE-2020-24442MEDIUMReflected Cross-Site Scripting (XSS) in Adobe ConnectEPSS 1.5%CVE-2021-25313HIGHRancher: XSS on /v3/cluster/EPSS 1.5%CVE-2020-24443MEDIUMReflected Cross-Site Scripting (XSS) in Adobe ConnectEPSS 1.5%CVE-2023-35155HIGHXWiki Platform vulnerable to cross-site scripting in target parameter via share page by emailEPSS 1.5%CVE-2021-39201HIGHAuthenticated cross-site scripting (XSS) in WordPress editorEPSS 1.5%CVE-2018-0206—A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attackeEPSS 1.5%CVE-2017-12288—A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthenticated, remote attackeEPSS 1.5%CVE-2017-12356—A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remEPSS 1.5%CVE-2017-12296—A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attacEPSS 1.5%CVE-2018-0091—A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 1.5%CVE-2017-12366—A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attackEPSS 1.5%CVE-2018-0093—A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker EPSS 1.5%CVE-2017-12298—A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attackEPSS 1.5%CVE-2017-12265—A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, reEPSS 1.5%CVE-2018-0200—A vulnerability in the web-based interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to conduct a refleEPSS 1.5%CVE-2017-12304—A vulnerability in the IOS daemon (IOSd) web-based management interface of Cisco IOS and IOS XE Software could allow an unauthenticated, remEPSS 1.5%