Falhas do tipo CWE-79

28.635 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando a aplicação insere dados não validados do usuário diretamente em páginas HTML enviadas ao navegador, permitindo que atacantes injetem código JavaScript malicioso. O navegador executa esse script com os mesmos privilégios da sessão legítima, comprometendo dados da vítima ou sua conta.

Exemplo

Um formulário de busca que exibe o termo digitado na página sem sanitização: se você buscar por '<script>alert(1)</script>', esse script será executado no navegador de quem abrir o resultado. Um atacante pode roubar cookies de sessão ou redirecionar para um site falso.

Como mitigar

Valide e escape todos os dados do usuário antes de renderizar em HTML (use funções nativas como textContent em vez de innerHTML). Para entrada de dados, liste o que é permitido (whitelist); para saída, contextualize o escape (HTML, JavaScript, URL). Use Content Security Policy (CSP) como camada adicional para restringir execução de scripts inline.

CVE-2023-33132MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.9%CVE-2020-1607HIGHJunos OS: Cross-Site Scripting (XSS) in J-WebEPSS 0.9%CVE-2020-7354MEDIUMRapid7 Metasploit Pro Stored XSS in 'host' fieldEPSS 0.9%CVE-2020-7355MEDIUMRapid7 Metasploit Pro Stored XSS in 'notes' fieldEPSS 0.9%CVE-2024-24574MEDIUMphpMyFAQ vulnerable to stored XSS on attachments filenameEPSS 0.9%CVE-2021-25041—Photo Gallery by 10Web < 1.5.68 - Reflected Cross-Site Scripting (XSS)EPSS 0.9%CVE-2026-33168LOWRails has a possible XSS vulnerability in its Action View tag helpersEPSS 0.9%CVE-2024-50859MEDIUMThe ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly formatted file, the conteEPSS 0.9%CVE-2026-22029HIGHReact Router vulnerable to XSS via Open RedirectsEPSS 0.9%CVE-2023-26773MEDIUMCross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the producEPSS 0.9%CVE-2023-4771MEDIUMCross-Site Scripting vulnerability in CKSource CKEditorEPSS 0.9%CVE-2018-16861HIGHA cross-site scripting (XSS) flaw was found in the foreman component of satellite. An attacker with privilege to create entries using the HoEPSS 0.9%CVE-2024-27132HIGHInsufficient sanitization in MLflow leads to XSS when running an untrusted recipe.EPSS 0.9%CVE-2018-6588—CA API Developer Portal 3.5 up to and including 3.5 CR5 has a reflected cross-site scripting vulnerability related to the apiExplorer.EPSS 0.9%CVE-2018-6586—CA API Developer Portal 3.5 up to and including 3.5 CR6 has a stored cross-site scripting vulnerability related to profile picture processinEPSS 0.9%CVE-2021-4139MEDIUMCross-site Scripting (XSS) - Stored in pimcore/pimcoreEPSS 0.9%CVE-2024-0286MEDIUMPHPGurukul Hospital Management System Contact Form index.php#contact_us cross site scriptingEPSS 0.9%CVE-2018-6587—CA API Developer Portal 3.5 up to and including 3.5 CR6 has a reflected cross-site scripting vulnerability related to the widgetID variable.EPSS 0.9%CVE-2022-0601—Countdown & Clock < 2.2.9 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-25027—PowerPack Addons for Elementor < 2.6.2 - Reflected Cross-Site ScriptingEPSS 0.9%