Weaknesses of type CWE-94
4,495 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2025-9590MEDIUMWeaver E-Mobile Mobile Management Platform cross site scriptingEPSS 0.3%CVE-2026-100882MEDIUMKrayin laravel-crm Admin Settings Endpoint index.blade.php cross site scriptingEPSS 0.3%CVE-2025-8551MEDIUMatjiu pybbs list cross site scriptingEPSS 0.3%CVE-2025-13245MEDIUMcode-projects Student Information System editprofile.php cross site scriptingEPSS 0.3%CVE-2025-23361HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause impropeEPSS 0.3%CVE-2025-7111MEDIUMPortabilis i-Educar Course Module educar_curso_det.php cross site scriptingEPSS 0.3%CVE-2025-15052MEDIUMcode-projects Student Information System profile.php cross site scriptingEPSS 0.3%CVE-2025-13469MEDIUMPublic Knowledge Project omp/ojs Payment Instructions Setting paymentForm.tpl cross site scriptingEPSS 0.3%CVE-2026-66150HIGHImproper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated atEPSS 0.3%CVE-2025-7110MEDIUMPortabilis i-Educar School Module educar_escola_lst.php cross site scriptingEPSS 0.3%CVE-2025-13202MEDIUMcode-projects Simple Cafe Ordering System add_to_cart cross site scriptingEPSS 0.3%CVE-2025-7941MEDIUMPHPGurukul Time Table Generator System profile.php cross site scriptingEPSS 0.3%CVE-2026-11688HIGHInappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a saEPSS 0.3%CVE-2025-13349MEDIUMSourceCodester Student Grades Management System Add New Grade grades.php cross site scriptingEPSS 0.3%CVE-2025-14194MEDIUMcode-projects Employee Profile Management System view_personnel.php cross site scriptingEPSS 0.3%CVE-2026-58572HIGHDell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerEPSS 0.3%CVE-2025-8506MEDIUM495300897 wx-shop editUI cross site scriptingEPSS 0.3%CVE-2026-66149HIGHImproper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated atEPSS 0.3%CVE-2025-15374MEDIUMEyouCMS Ask Module Ask.php cross site scriptingEPSS 0.3%CVE-2025-7113MEDIUMPortabilis i-Educar Curricular Components Module edit cross site scriptingEPSS 0.3%