Falhas do tipo CWE-79

28.619 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2021-34644MEDIUMMultiplayer Games <= 3.7 Reflected Cross-Site ScriptingEPSS 0.9%CVE-2017-16019—GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-EPSS 0.9%CVE-2022-2685LOWSourceCodester Interview Management System addQuestion.php cross site scriptingEPSS 0.9%CVE-2023-52329MEDIUMCertain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an atEPSS 0.9%CVE-2023-7312MEDIUMNagios Fusion < 4.2.0 Email Settings Stored XSS via SMTP/sendmailEPSS 0.9%CVE-2026-7569HIGHQuest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass VulnerabilityEPSS 0.9%CVE-2026-9780HIGHQuest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass VulnerabilityEPSS 0.9%CVE-2023-38164HIGHMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 0.9%CVE-2022-1087LOWhtmly Edit Profile Module cross site scriptingEPSS 0.9%CVE-2025-4859MEDIUMD-Link DAP-2695 MAC Bypass Settings Page adv_macbypass.php cross site scriptingEPSS 0.9%CVE-2019-10957—Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote auEPSS 0.9%CVE-2020-25631—A vulnerability was found in Moodle 3.9 to 3.9.1, 3.8 to 3.8.4 and 3.7 to 3.7.7 where it was possible to include JavaScript in a book's chapEPSS 0.9%CVE-2017-15125MEDIUMA flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTEPSS 0.9%CVE-2020-8245—Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, EPSS 0.9%CVE-2022-24870HIGHStored Cross-site Scripting in Combodo iTopEPSS 0.9%CVE-2023-21565HIGHAzure DevOps Server Spoofing VulnerabilityEPSS 0.9%CVE-2024-33905MEDIUMIn Telegram WebK before 2.0.0 (488), a crafted Mini Web App allows XSS via the postMessage web_app_open_link event type.EPSS 0.9%CVE-2022-36107MEDIUMStored Cross-Site Scripting via FileDumpControllerEPSS 0.9%CVE-2020-15161MEDIUMPotential XSS in PrestaShopEPSS 0.9%CVE-2019-14884MEDIUMA vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal eEPSS 0.9%