Weaknesses of type CWE-94
4,457 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2022-28766LOWDLL injection in Zoom Windows ClientsEPSS 0.5%CVE-2026-89276CRITICALAdobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)EPSS 0.5%CVE-2024-13012MEDIUMcode-projects Hostel Management System registration.php cross site scriptingEPSS 0.5%CVE-2026-40322CRITICALSiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCEEPSS 0.5%CVE-2025-25507MEDIUMThere is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote commanEPSS 0.5%CVE-2024-11246MEDIUMcode-projects Farmacia adicionar-cliente.php cross site scriptingEPSS 0.5%CVE-2025-66562HIGHTUUI vulnerable to Remote Code Execution (RCE) via XSS in Markdown ECharts RenderingEPSS 0.5%CVE-2025-11548CRITICALibi WebFOCUS - Unauthenticated RCE VulnerabilityEPSS 0.5%CVE-2024-12503MEDIUMClassCMS Model Management Page admin cross site scriptingEPSS 0.5%CVE-2024-37405MEDIUMLivechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistEPSS 0.5%CVE-2025-2805HIGHORDER POST <= 2.0.2 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2026-18385MEDIUMPaid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.19 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile FieldEPSS 0.5%CVE-2025-51427HIGHAn issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration filEPSS 0.5%CVE-2026-35211MEDIUMOpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoSEPSS 0.5%CVE-2025-2809HIGHazurecurve Shortcodes in Comments <= 2.0.2 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2025-24243HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, mEPSS 0.5%CVE-2026-41149MEDIUMMermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injectionEPSS 0.5%CVE-2026-23742HIGHSkipper arbitrary code execution through lua filtersEPSS 0.5%CVE-2025-61196HIGHAn issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter.EPSS 0.5%CVE-2026-3424MEDIUMkk Star Ratings <= 5.4.10.3 - Unauthenticated Arbitrary Shortcode Execution via 'payload' ParameterEPSS 0.5%