Fallos del tipo CWE-94

4457 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2026-59833HIGHSiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)EPSS 0.5%CVE-2026-51385MEDIUMAn issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url,EPSS 0.5%CVE-2024-38448CRITICALhtags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may EPSS 0.5%CVE-2024-33335MEDIUMSQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.EPSS 0.5%CVE-2025-3554MEDIUMphpshe api.php cross site scriptingEPSS 0.5%CVE-2025-60206CRITICALWordPress Alone theme <= 7.8.3 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2023-6540MEDIUMA vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payEPSS 0.5%CVE-2023-51320MEDIUMPHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. ThEPSS 0.5%CVE-2026-37713HIGHAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/EPSS 0.5%CVE-2026-9196HIGHLangflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handlingEPSS 0.5%CVE-2026-58074HIGHA vulnerability allowing a high-privileged user to execute arbitrary code on the server.EPSS 0.5%CVE-2026-81662HIGHFlowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configuration KeysEPSS 0.5%CVE-2026-4813CRITICALCode injection in the Lutece CoreEPSS 0.5%CVE-2023-43352—An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu compoEPSS 0.5%CVE-2026-37711HIGHAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/EPSS 0.5%CVE-2024-13814MEDIUMGlobal Gallery - WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2026-37712HIGHAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/EPSS 0.5%CVE-2025-1742MEDIUMpihome-shc PiHome home.php cross site scriptingEPSS 0.5%CVE-2026-60026HIGHJoomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1EPSS 0.5%CVE-2022-2054HIGHCode Injection in nuitka/nuitkaEPSS 0.5%