Falhas do tipo CWE-80

586 resultados

Falta de neutralização de tags HTML relacionadas a scripts (XSS básico)

Ocorre quando a aplicação web recebe entrada do usuário e a exibe no HTML sem sanitizar tags de script e eventos (como <script>, onclick, onerror). Um atacante injeta código JavaScript malicioso que executa no navegador da vítima, roubando cookies, sessões ou dados sensíveis.

Exemplo

Um formulário de comentários aceita '<img src=x onerror="alert(document.cookie)">'. A aplicação exibe o comentário sem filtro na página, e o navegador executa o código malicioso quando carrega a imagem inválida, capturando a sessão do usuário.

Como mitigar

Escape ou remova todas as tags HTML perigosas antes de renderizar (use bibliotecas como DOMPurify ou sanitizadores nativos da stack). Aplique Content Security Policy (CSP) nos headers HTTP para bloquear inline scripts mesmo que a injeção passe.

CVE-2025-55672MEDIUMApache Superset: Stored XSS on charts metadataEPSS 0.7%CVE-2019-6585A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCAEPSS 0.7%CVE-2018-25034LOWThomson TCW710 wlanPrimaryNetwork Persistent cross site scriptingEPSS 0.7%CVE-2017-20089LOWGwolle Guestbook Plugin cross site scritingEPSS 0.7%CVE-2017-20087LOWAlpine PhotoTile for Instagram Plugin cross site scritingEPSS 0.7%CVE-2023-42458LOWZope vulnerable to Stored Cross Site Scripting with SVG imagesEPSS 0.7%CVE-2026-75872MEDIUMHTML Injection in MailerUp double opt-in verification emailEPSS 0.7%CVE-2017-20100LOWAir Transfer cross site scriptingEPSS 0.7%CVE-2021-29438MEDIUMImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in @nextcloud/dialogsEPSS 0.7%CVE-2022-1274A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to KeycEPSS 0.7%CVE-2018-16555A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All EPSS 0.7%CVE-2023-33197MEDIUMCraft CMS stored XSS in indexedVolumesEPSS 0.7%CVE-2026-52816MEDIUMGogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSSEPSS 0.7%CVE-2023-5933MEDIUMImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLabEPSS 0.7%CVE-2023-2981LOWAbstrium Pydio Cells Chat cross site scriptingEPSS 0.7%CVE-2024-34507HIGHAn issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1EPSS 0.7%CVE-2020-15788A vulnerability has been identified in Polarion Subversion Webclient (All versions). The Polarion subversion web application does not filterEPSS 0.7%CVE-2026-32773MEDIUMApache Spark: XSS Vulnerability in Spark Web 3.5.4EPSS 0.7%CVE-2024-27306MEDIUMaiohttp vulnerable to XSS on index pages for static file handlingEPSS 0.7%CVE-2020-7575A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (All versions < V11.3EPSS 0.7%