Falhas do tipo CWE-79

28.634 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2026-64638HIGHWordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party websEPSS 0.9%CVE-2020-8020MEDIUMPersistent XSS in markdown parser used by obs-serverEPSS 0.9%CVE-2021-24681—Duplicate Page <= 4.4.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.9%CVE-2026-32118MEDIUMOpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation textEPSS 0.9%CVE-2024-3850MEDIUMUniview NVR301-04S2-P4 Cross-site ScriptingEPSS 0.9%CVE-2022-1005—WP Statistics < 13.2.2 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25955CRITICALStored XSS in “Dolibarr” leads to privilege escalationEPSS 0.9%CVE-2022-23518MEDIUMImproper neutralization of data URIs allows XSS in rails-html-sanitizerEPSS 0.9%CVE-2024-22195MEDIUMJinja vulnerable to Cross-Site Scripting (XSS)EPSS 0.9%CVE-2025-41228MEDIUMVMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) VulnerabilityEPSS 0.9%CVE-2017-12348—Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a crosEPSS 0.9%CVE-2017-12349—Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a crosEPSS 0.9%CVE-2023-39360MEDIUMReflected Cross-site Scripting in graphs_new.php in CactiEPSS 0.9%CVE-2018-0201—A vulnerability in Cisco Jabber Client Framework (JCF) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS)EPSS 0.9%CVE-2017-12294—A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack EPSS 0.9%CVE-2017-12357—A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker EPSS 0.9%CVE-2020-10614—In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject EPSS 0.9%CVE-2018-3824—X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject datEPSS 0.9%CVE-2018-15633HIGHCross-site scripting (XSS) issue in "document" module in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remoteEPSS 0.9%CVE-2024-43476HIGHMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 0.9%