Falhas do tipo CWE-80

586 resultados

Falta de neutralização de tags HTML relacionadas a scripts (XSS básico)

Ocorre quando a aplicação web recebe entrada do usuário e a exibe no HTML sem sanitizar tags de script e eventos (como <script>, onclick, onerror). Um atacante injeta código JavaScript malicioso que executa no navegador da vítima, roubando cookies, sessões ou dados sensíveis.

Exemplo

Um formulário de comentários aceita '<img src=x onerror="alert(document.cookie)">'. A aplicação exibe o comentário sem filtro na página, e o navegador executa o código malicioso quando carrega a imagem inválida, capturando a sessão do usuário.

Como mitigar

Escape ou remova todas as tags HTML perigosas antes de renderizar (use bibliotecas como DOMPurify ou sanitizadores nativos da stack). Aplique Content Security Policy (CSP) nos headers HTTP para bloquear inline scripts mesmo que a injeção passe.

CVE-2024-9438MEDIUMSEUR Oficial <= 2.2.11 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2024-32966MEDIUMStored Cross-site Scripting in directory listings via file names in static-web-serverEPSS 0.4%CVE-2026-54443MEDIUMDashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)EPSS 0.4%CVE-2025-1807MEDIUMEastnets PaymentSafe Edit Manual Reply directRouter.rfc cross site scriptingEPSS 0.4%CVE-2021-44196MEDIUMXSS in UBIT Information Technologies Student Information Management SystemEPSS 0.4%CVE-2023-43790MEDIUMiTop vulnerable to XSS in friendlyname in object detailsEPSS 0.4%CVE-2021-44197MEDIUMXSS in UBIT Information Technologies Student Information Management SystemEPSS 0.4%CVE-2024-52967LOWAn improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attackeEPSS 0.4%CVE-2023-49852MEDIUMWordPress Responsive Slick Slider WordPress plugin <= 1.4 - Content Injection vulnerabilityEPSS 0.4%CVE-2023-20257MEDIUMA vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conductEPSS 0.4%CVE-2025-53835CRITICALXWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntaxEPSS 0.4%CVE-2023-47513MEDIUMWordPress ARI Stream Quiz – WordPress Quizzes Builder plugin <= 1.3.2 - Content Injection vulnerabilityEPSS 0.4%CVE-2023-1013MEDIUMXSS in Vira-InvestingEPSS 0.4%CVE-2024-11404MEDIUMFile Upload Bypass in django FilerEPSS 0.4%CVE-2025-39524MEDIUMWordPress Html5 Audio Player plugin <= 2.2.28 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.4%CVE-2024-10038MEDIUMWP-Strava <= 2.12.1 - Authenticated (Administrator+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2024-45406MEDIUMCraft CMS stored XSS in breadcrumb list and title fieldsEPSS 0.4%CVE-2024-12127MEDIUMLearning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS <= 0.0.21 - Reflected Cross-Site Scripting via page ParameterEPSS 0.4%CVE-2023-51308MEDIUMPHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, EPSS 0.4%CVE-2023-20179MEDIUMA vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenEPSS 0.4%