Weaknesses of type CWE-94
4,480 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2025-3036MEDIUMyzk2356911358 StudentServlet-JSP Student Management cross site scriptingEPSS 0.3%CVE-2025-5407MEDIUMchaitak-gorai Blogbook register_script.php cross site scriptingEPSS 0.3%CVE-2025-5721MEDIUMSourceCodester Student Result Management System Profile Setting Page update_profile cross site scriptingEPSS 0.3%CVE-2025-11278MEDIUMAllStarLink Supermon AllMon2 cross site scriptingEPSS 0.3%CVE-2025-7567MEDIUMShopXO header.html cross site scriptingEPSS 0.3%CVE-2026-3819MEDIUMSourceCodester Resort Reservation System Reservation Management page cross site scriptingEPSS 0.3%CVE-2026-100857HIGHAzuraCast before 0.23.4 Remote Code Execution via Liquidsoap string interpolationEPSS 0.3%CVE-2026-3766MEDIUMSourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site scriptingEPSS 0.3%CVE-2025-6849MEDIUMcode-projects Simple Forum forum_edit1.php cross site scriptingEPSS 0.3%CVE-2025-10590MEDIUMPortabilis i-Educar educar_usuario_det.php cross site scriptingEPSS 0.3%CVE-2025-9736MEDIUMO2OA Personal Profile statement cross site scriptingEPSS 0.3%CVE-2025-9718MEDIUMO2OA Personal Profile process cross site scriptingEPSS 0.3%CVE-2025-9737MEDIUMO2OA Personal Profile importmodel cross site scriptingEPSS 0.3%CVE-2025-5135MEDIUMTmall Demo Product Details Page admin cross site scriptingEPSS 0.3%CVE-2024-25086HIGHImproper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.EPSS 0.3%CVE-2025-9734MEDIUMO2OA Personal Profile stat cross site scriptingEPSS 0.3%CVE-2025-4208MEDIUMNEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records FunctionEPSS 0.3%CVE-2024-29409MEDIUMFile Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.EPSS 0.3%CVE-2025-7951MEDIUMcode-projects Public Chat Room send_message.php cross site scriptingEPSS 0.3%CVE-2025-65715HIGHAn issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary cEPSS 0.3%