VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 118 of 350
  • CVE-2026-34585HigMar 31, 2026
    risk 0.49cvss 8.6epss 0.00

    SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a…

  • CVE-2026-33955HigMar 27, 2026
    risk 0.49cvss 8.6epss 0.00

    Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note…

  • CVE-2026-4276HigMar 16, 2026
    risk 0.49cvss 7.5epss 0.00

    LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.

  • CVE-2020-37178HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.00

    KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.

  • CVE-2025-61732HigFeb 5, 2026
    risk 0.49cvss 8.6epss 0.00

    A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

  • CVE-2025-69319HigJan 22, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Beaver Builder Beaver Builder beaver-builder-lite-version allows Code Injection.This issue affects Beaver Builder: from n/a through <= 2.9.4.1.

  • CVE-2025-68924HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.01

    In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.

  • CVE-2025-61488HigOct 20, 2025
    risk 0.49cvss 7.6epss 0.00

    An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php component and the imageURL parameter

  • CVE-2025-61590HigOct 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual Studio Code Workspaces. Workspaces allow users to open more than a single folder and save specific settings (pretty similar to…

  • CVE-2025-11153HigSep 30, 2025
    risk 0.49cvss 7.5epss 0.00

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.

  • CVE-2025-59251HigSep 24, 2025
    risk 0.49cvss 7.6epss 0.00

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2025-58444HigSep 8, 2025
    risk 0.49cvss epss 0.01

    The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This…

  • CVE-2025-9959HigSep 3, 2025
    risk 0.49cvss 7.6epss 0.00

    Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.

  • CVE-2025-52218HigAug 26, 2025
    risk 0.49cvss 7.5epss 0.00

    SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified parameters allows attackers to inject arbitrary text or limited HTML into the login page.

  • CVE-2025-30975HigAug 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Code Injection.This issue affects Add Custom Codes: from n/a through <= 4.80.

  • CVE-2025-55192HigAug 14, 2025
    risk 0.49cvss epss 0.00

    HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home Assistant integration…

  • CVE-2025-4056HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines.

  • CVE-2025-37105HigJul 16, 2025
    risk 0.49cvss 7.5epss 0.01

    An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

  • CVE-2025-47988HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.

  • CVE-2025-26621HigMay 19, 2025
    risk 0.49cvss 7.6epss 0.00

    OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with the capability manage customizations can edit webhook that will execute javascript code. This can be abused to cause a denial of service…