Weaknesses of type CWE-94

4,449 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2026-77939HIGHFlextype CMS 1.0.0-dev RCE via POST /api/v1/query EndpointEPSS 0.6%CVE-2024-9837HIGHAADMY – Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.6%CVE-2025-52122CRITICALFreeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitEPSS 0.6%CVE-2026-24887HIGHClaude Code has a Command Injection in find Command Bypasses User Approval PromptEPSS 0.6%CVE-2026-92127HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when EPSS 0.6%CVE-2025-1615MEDIUMFiberHome AN5506-01A ONU GPON NAT Submenu cross site scriptingEPSS 0.6%CVE-2025-9517HIGHatec Debug <= 1.2.22 - Authenticated (Administrator+) Remote Code ExecutionEPSS 0.6%CVE-2024-45198HIGHinsightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, trEPSS 0.6%CVE-2024-48962HIGHApache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE)EPSS 0.6%CVE-2024-45199HIGHinsightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC EPSS 0.6%CVE-2023-54345HIGHFrappe Framework ERPNext 13.4.0 Remote Code ExecutionEPSS 0.6%CVE-2024-10899HIGHWooCommerce Product Table Lite <= 3.8.6 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site ScriptingEPSS 0.6%CVE-2025-66222CRITICALDeepChat Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE)EPSS 0.6%CVE-2026-21853HIGHAFFiNE: One-click Remote Code Execution through Custom URL HandlingEPSS 0.6%CVE-2024-6946MEDIUMFlute CMS list code injectionEPSS 0.6%CVE-2024-36679CRITICALIn the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictaEPSS 0.6%CVE-2024-10262MEDIUMDrop Shadow Boxes <= 1.7.14 - Authenticated (Subscriber+) Arbitrary Shortcode ExecutionEPSS 0.6%CVE-2021-23154MEDIUMCommand injection in Lens causes arbitrary shell command execution when malicious custom helm chart configuration providedEPSS 0.6%CVE-2024-55529CRITICALZ-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.EPSS 0.6%CVE-2026-64633CRITICALA vulnerability allowing remote unauthenticated code execution on the agent host.EPSS 0.6%