VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 124 of 350
  • CVE-2023-43651HigSep 27, 2023
    risk 0.48cvss 8.5epss 0.02

    JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leading to remote code execution. This vulnerability may further be leveraged to gain root privileges on the system. Through the WEB…

  • CVE-2023-29400HigMay 11, 2023
    risk 0.48cvss 7.3epss 0.01

    Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

  • CVE-2023-24539HigMay 11, 2023
    risk 0.48cvss 7.3epss 0.01

    Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with…

  • CVE-2023-1250HigMar 20, 2023
    risk 0.48cvss 7.4epss 0.00

    Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via manipulated comments and ACL-names This…

  • CVE-2023-24059HigJan 22, 2023
    risk 0.48cvss 7.3epss 0.02

    Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.

  • CVE-2017-20099HigJun 27, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.

  • CVE-2022-2054HigJun 12, 2022
    risk 0.48cvss 8.4epss 0.01

    Code Injection in GitHub repository nuitka/nuitka prior to 0.9.

  • CVE-2021-43837HigDec 16, 2021
    risk 0.48cvss 8.4epss 0.05

    vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest…

  • CVE-2021-31949HigJun 8, 2021
    risk 0.48cvss 7.3epss 0.03

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2021-29505HigMay 28, 2021
    risk 0.48cvss 7.5epss 0.77

    XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the…

  • CVE-2021-21277HigFeb 1, 2021
    risk 0.48cvss 8.5epss 0.03

    angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you call "expressions.compile(userControlledInput)" where…

  • CVE-2019-15001HigSep 19, 2019
    risk 0.48cvss 7.2epss 0.11

    The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator…

  • CVE-2016-7966HigDec 23, 2016
    risk 0.48cvss 7.3epss 0.03

    Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available…

  • CVE-2026-17581HigAug 16, 2026
    risk 0.47cvss 7.2epss 0.01

    The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all versions up to, and including, 1.9.14 due to the Receipt_Renderer_Factory dispatching templates with the 'thermal' engine to the…

  • CVE-2026-73679HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.01

    ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded…

  • CVE-2026-71232HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.00

    MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function,…

  • CVE-2026-18770HigAug 4, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is…

  • CVE-2026-54666HigJul 29, 2026
    risk 0.47cvss 8.3epss 0.00

    swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs…

  • CVE-2026-54664HigJul 29, 2026
    risk 0.47cvss 8.3epss 0.00

    swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before…

  • CVE-2026-54662HigJul 29, 2026
    risk 0.47cvss 8.3epss 0.00

    swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates…