Weaknesses of type CWE-94

4,495 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2025-2976MEDIUMGFI KerioConnect File Upload cross site scriptingEPSS 0.3%CVE-2025-8510MEDIUMPortabilis i-Educar educar_matricula_lst.php Gerar cross site scriptingEPSS 0.3%CVE-2024-28893HIGHCertain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been EPSS 0.3%CVE-2025-14201MEDIUMalokjaiswal Hotel-Management-services-using-MYSQL-and-php dishsub.php cross site scriptingEPSS 0.3%CVE-2026-2160MEDIUMSourceCodester Simple Responsive Tourism Website Master.php cross site scriptingEPSS 0.3%CVE-2025-9306MEDIUMSourceCodester Advanced School Management System addNotice cross site scriptingEPSS 0.3%CVE-2025-10631MEDIUMitsourcecode Online Petshop Management System Available Products addcnp.php cross site scriptingEPSS 0.3%CVE-2025-10632MEDIUMitsourcecode Online Petshop Management System Admin Dashboard availableframe.php cross site scriptingEPSS 0.3%CVE-2026-22314HIGHVendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissioEPSS 0.3%CVE-2026-10173MEDIUMOrthanc Explorer 2 URL StudyList.vue cross site scriptingEPSS 0.3%CVE-2026-0730MEDIUMPHPGurukul Staff Leave Management System SVG File adminviews.py UPDATE_STAFF cross site scriptingEPSS 0.3%CVE-2026-84462HIGHZammad: AI Agent template sanitizer bypass leads to remote code executionEPSS 0.3%CVE-2025-31365MEDIUMAn Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2EPSS 0.3%CVE-2026-23808MEDIUMClient Isolation Bypass via GTK ManipulationEPSS 0.3%CVE-2024-54997MEDIUMMonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/EPSS 0.3%CVE-2025-66533MEDIUMWordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerabilityEPSS 0.3%CVE-2022-22286MEDIUMA vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows atEPSS 0.3%CVE-2026-12822MEDIUMlangflow-ai langflow Bundle URL Loader code injectionEPSS 0.3%CVE-2022-22285MEDIUMA vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attEPSS 0.3%CVE-2025-8750MEDIUMmacrozheng mall Add Product Page upload cross site scriptingEPSS 0.3%