Falhas do tipo CWE-80

586 resultados

Falta de neutralização de tags HTML relacionadas a scripts (XSS básico)

Ocorre quando a aplicação web recebe entrada do usuário e a exibe no HTML sem sanitizar tags de script e eventos (como <script>, onclick, onerror). Um atacante injeta código JavaScript malicioso que executa no navegador da vítima, roubando cookies, sessões ou dados sensíveis.

Exemplo

Um formulário de comentários aceita '<img src=x onerror="alert(document.cookie)">'. A aplicação exibe o comentário sem filtro na página, e o navegador executa o código malicioso quando carrega a imagem inválida, capturando a sessão do usuário.

Como mitigar

Escape ou remova todas as tags HTML perigosas antes de renderizar (use bibliotecas como DOMPurify ou sanitizadores nativos da stack). Aplique Content Security Policy (CSP) nos headers HTTP para bloquear inline scripts mesmo que a injeção passe.

CVE-2025-66481CRITICALDeepChat's Incomplete XSS Fix Allows RCE through Mermaid ContentEPSS 0.6%CVE-2022-39277MEDIUMCross-Site Scripting (XSS) in external links in GLPIEPSS 0.6%CVE-2024-25639MEDIUMPrompt Injection triggered XSS vulnerability in Khoj Obsidian, Desktop and Web clientsEPSS 0.6%CVE-2023-24497MEDIUMCross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-EPSS 0.6%CVE-2023-24496MEDIUMCross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-EPSS 0.6%CVE-2023-22461HIGHsanitize-svg Filter Bypass Allows Cross-Site Scripting (XSS)EPSS 0.6%CVE-2024-46910HIGHApache Atlas: An authenticated user can perform XSS and potentially impersonate another userEPSS 0.6%CVE-2022-35509MEDIUMAn issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts EPSS 0.6%CVE-2017-20043MEDIUMNavetti PricePoint Persistent cross site scritingEPSS 0.6%CVE-2017-20044MEDIUMNavetti PricePoint Reflected cross site scritingEPSS 0.6%CVE-2023-41048LOWplone.namedfile vulnerable to Stored Cross Site Scripting with SVG imagesEPSS 0.6%CVE-2022-20765MEDIUMCisco UCS Director JavaScript Cross-Site Scripting VulnerabilityEPSS 0.6%CVE-2025-39663HIGHCross Site Scripting through compromised remote siteEPSS 0.6%CVE-2022-25756A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE XEPSS 0.6%CVE-2024-32472MEDIUMexcalidraw vulnerable to a Stored XSS in excalidraw's web embed componentEPSS 0.6%CVE-2026-24128MEDIUMXWiki Affected by Reflected Cross-Site Scripting (XSS) in Error MessagesEPSS 0.6%CVE-2024-33423HIGHCross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML viEPSS 0.6%CVE-2024-23817HIGHDolibarr Application Home Page HTML injection vulnerabilityEPSS 0.6%CVE-2024-34699MEDIUMGZ::CTF allows unprivileged user can perform XSS attacks by constructing malicious team names.EPSS 0.5%CVE-2024-0183LOWRRJ Nueva Ecija Engineer Online Portal NIA Office students.php cross site scriptingEPSS 0.5%