Weaknesses of type CWE-94
4,460 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2026-61536HIGHBanks: Unsafe importlib.import_module of attacker-controlled Tool.import_path in CompletionExtension allows RCEEPSS 0.5%CVE-2024-7093CRITICALServer-Side Template Injection in Dispatch Message TemplatesEPSS 0.5%CVE-2025-65099HIGHClaude Code vulnerable to command execution prior to startup trust dialogEPSS 0.5%CVE-2024-37124CRITICALUse of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may creEPSS 0.5%CVE-2024-35226HIGHPHP Code Injection by malicious attribute in extends-tag in SmartyEPSS 0.5%CVE-2024-12980MEDIUMcode-projects Job Recruitment _all_edits.php fln_update cross site scriptingEPSS 0.5%CVE-2024-12979MEDIUMcode-projects Job Recruitment _all_edits.php cn_update cross site scriptingEPSS 0.5%CVE-2025-0844MEDIUMneedyamin Library Card System Registration Page signup.php cross site scriptingEPSS 0.5%CVE-2024-46076CRITICALRuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection ofEPSS 0.5%CVE-2026-82666MEDIUMyaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injectionEPSS 0.5%CVE-2026-62674CRITICALOmnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEEPSS 0.5%CVE-2025-11344MEDIUMILIAS Certificate Import code injectionEPSS 0.5%CVE-2025-24677CRITICALWordPress Post/Page Copying Tool to Export and Import post/page for Cross site Migration Plugin <= 2.0.3 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2024-44722CRITICALSysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.EPSS 0.5%CVE-2026-76635HIGHbaserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.phpEPSS 0.5%CVE-2024-11733HIGHWordPress Popular Posts <= 7.1.0 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2026-58025MEDIUMRemote Code Execution via Unsafe Deserialization in LogItem ImportEPSS 0.5%CVE-2025-56588HIGHDolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the cEPSS 0.5%CVE-2025-9334HIGHBetter Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code InjectionEPSS 0.5%CVE-2025-63665CRITICALAn issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payEPSS 0.5%