Falhas do tipo CWE-80

586 resultados

Falta de neutralização de tags HTML relacionadas a scripts (XSS básico)

Ocorre quando a aplicação web recebe entrada do usuário e a exibe no HTML sem sanitizar tags de script e eventos (como <script>, onclick, onerror). Um atacante injeta código JavaScript malicioso que executa no navegador da vítima, roubando cookies, sessões ou dados sensíveis.

Exemplo

Um formulário de comentários aceita '<img src=x onerror="alert(document.cookie)">'. A aplicação exibe o comentário sem filtro na página, e o navegador executa o código malicioso quando carrega a imagem inválida, capturando a sessão do usuário.

Como mitigar

Escape ou remova todas as tags HTML perigosas antes de renderizar (use bibliotecas como DOMPurify ou sanitizadores nativos da stack). Aplique Content Security Policy (CSP) nos headers HTTP para bloquear inline scripts mesmo que a injeção passe.

CVE-2024-26482HIGHAn HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes the significance of EPSS 0.3%CVE-2024-20460MEDIUMCisco ATA 190 Series Analog Telephone Adapter Firmware Reflected Cross-Site Scripting VulnerabilityEPSS 0.3%CVE-2019-18944MEDIUMMicro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.EPSS 0.3%CVE-2025-57928MEDIUMWordPress AWP Classifieds plugin <= 4.4.3 - Content Injection vulnerabilityEPSS 0.3%CVE-2024-13497HIGHWordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.3%CVE-2025-64225MEDIUMWordPress Stockie Extra plugin <= 1.2.11 - Content Injection vulnerabilityEPSS 0.3%CVE-2023-46235MEDIUMFOG stored XSS on log screen via unsanitized request loggingEPSS 0.3%CVE-2026-54570MEDIUMAngleSharp: HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point BypassEPSS 0.3%CVE-2026-25578MEDIUMNavidrome is vulnerable to XSS via comment from song metadataEPSS 0.3%CVE-2023-48285MEDIUMWordPress Accept Stripe Payments plugin <= 2.0.79 - Content Injection vulnerabilityEPSS 0.3%CVE-2023-35006MEDIUMIBM Security ReaQta HTML injectionEPSS 0.3%CVE-2025-0276MEDIUMHCL BigFix Modern Client Management (MCM) is affected by an insecure Content Security Policy (CSP)EPSS 0.3%CVE-2025-0277MEDIUMHCL BigFix Mobile is affected by an insecure Content Security Policy (CSP)EPSS 0.3%CVE-2024-35112MEDIUMIBM Control Center cross-site scriptingEPSS 0.3%CVE-2023-47869MEDIUMWordPress wpForo plugin <= 2.2.5 - Broken Access Control + CSRF vulnerabilityEPSS 0.3%CVE-2025-52902HIGHFile Browser has Stored Cross-Site Scripting vulnerabilityEPSS 0.3%CVE-2025-10496HIGHCookie Notice & Consent <= 1.6.5 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-33080HIGHFilament: Unvalidated Range and Values summarizer values can be used for XSSEPSS 0.3%CVE-2026-57533LOWMalicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a CoEPSS 0.3%CVE-2025-27099MEDIUMTuleap allows XSS via the tracker names used in the semantic timeframe deletion messageEPSS 0.3%