Weaknesses of type CWE-94
4,457 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2026-59833HIGHSiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)EPSS 0.5%CVE-2026-51385MEDIUMAn issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url,EPSS 0.5%CVE-2024-38448CRITICALhtags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may EPSS 0.5%CVE-2024-33335MEDIUMSQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.EPSS 0.5%CVE-2025-3554MEDIUMphpshe api.php cross site scriptingEPSS 0.5%CVE-2025-60206CRITICALWordPress Alone theme <= 7.8.3 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2023-6540MEDIUMA vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payEPSS 0.5%CVE-2023-51320MEDIUMPHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. ThEPSS 0.5%CVE-2026-37713HIGHAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/EPSS 0.5%CVE-2026-9196HIGHLangflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handlingEPSS 0.5%CVE-2026-58074HIGHA vulnerability allowing a high-privileged user to execute arbitrary code on the server.EPSS 0.5%CVE-2026-81662HIGHFlowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configuration KeysEPSS 0.5%CVE-2026-4813CRITICALCode injection in the Lutece CoreEPSS 0.5%CVE-2023-43352—An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu compoEPSS 0.5%CVE-2026-37711HIGHAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/EPSS 0.5%CVE-2024-13814MEDIUMGlobal Gallery - WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2026-37712HIGHAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/EPSS 0.5%CVE-2025-1742MEDIUMpihome-shc PiHome home.php cross site scriptingEPSS 0.5%CVE-2026-60026HIGHJoomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1EPSS 0.5%CVE-2022-2054HIGHCode Injection in nuitka/nuitkaEPSS 0.5%