Weaknesses of type CWE-94
4,448 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2026-61962CRITICALWordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerabilityEPSS 0.7%CVE-2026-82340CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2024-37899CRITICALDisabling a user account changes its author, allowing RCE from user account in XWikiEPSS 0.7%CVE-2024-13929HIGHAuthenticated Servlet Command InjectionEPSS 0.7%CVE-2023-45560—An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.EPSS 0.7%CVE-2026-33976CRITICALNotesnook vulnerable to RCE via stored XSS in Web Clipper renderingEPSS 0.7%CVE-2024-11620HIGHWordPress Rank Math SEO plugin <= 1.0.231 - Arbitrary .htaccess Overwrite to Remote Code Execution (RCE) vulnerabilityEPSS 0.7%CVE-2024-9006MEDIUMjeanmarc77 123solar config_invt1.php code injectionEPSS 0.7%CVE-2026-29202MEDIUMInsufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the alEPSS 0.7%CVE-2026-41229CRITICALFroxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)EPSS 0.7%CVE-2024-31266CRITICALWordPress Advanced Order Export For WooCommerce plugin <= 3.4.4 - Remote Code Execution (RCE) vulnerabilityEPSS 0.7%CVE-2026-69254CRITICALFlowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions OverrideEPSS 0.7%CVE-2024-39015CRITICALcafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execEPSS 0.7%CVE-2019-5443—A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= EPSS 0.7%CVE-2025-1976HIGHCode injection exposure in Fabric OS 9.1.0 through 9.1.1d6EPSS 0.7%KEVCVE-2026-56446HIGHAuthenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISPEPSS 0.7%CVE-2020-8140—A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRAREPSS 0.7%CVE-2026-46633HIGHTwig: PHP code injection via `{% use %}` template nameEPSS 0.7%CVE-2025-25246HIGHNETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.EPSS 0.7%CVE-2025-23251HIGHNVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. EPSS 0.7%