Fallos del tipo CWE-94

4449 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2026-77939HIGHFlextype CMS 1.0.0-dev RCE via POST /api/v1/query EndpointEPSS 0.6%CVE-2024-9837HIGHAADMY – Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.6%CVE-2025-52122CRITICALFreeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitEPSS 0.6%CVE-2026-24887HIGHClaude Code has a Command Injection in find Command Bypasses User Approval PromptEPSS 0.6%CVE-2026-92127HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when EPSS 0.6%CVE-2025-1615MEDIUMFiberHome AN5506-01A ONU GPON NAT Submenu cross site scriptingEPSS 0.6%CVE-2025-9517HIGHatec Debug <= 1.2.22 - Authenticated (Administrator+) Remote Code ExecutionEPSS 0.6%CVE-2024-45198HIGHinsightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, trEPSS 0.6%CVE-2024-48962HIGHApache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE)EPSS 0.6%CVE-2024-45199HIGHinsightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC EPSS 0.6%CVE-2023-54345HIGHFrappe Framework ERPNext 13.4.0 Remote Code ExecutionEPSS 0.6%CVE-2024-10899HIGHWooCommerce Product Table Lite <= 3.8.6 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site ScriptingEPSS 0.6%CVE-2025-66222CRITICALDeepChat Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE)EPSS 0.6%CVE-2026-21853HIGHAFFiNE: One-click Remote Code Execution through Custom URL HandlingEPSS 0.6%CVE-2024-6946MEDIUMFlute CMS list code injectionEPSS 0.6%CVE-2024-36679CRITICALIn the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictaEPSS 0.6%CVE-2024-10262MEDIUMDrop Shadow Boxes <= 1.7.14 - Authenticated (Subscriber+) Arbitrary Shortcode ExecutionEPSS 0.6%CVE-2021-23154MEDIUMCommand injection in Lens causes arbitrary shell command execution when malicious custom helm chart configuration providedEPSS 0.6%CVE-2024-55529CRITICALZ-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.EPSS 0.6%CVE-2026-64633CRITICALA vulnerability allowing remote unauthenticated code execution on the agent host.EPSS 0.6%