VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 126 of 350
  • CVE-2026-5562HigApr 5, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code injection. The attack can be initiated remotely. The exploit is…

  • CVE-2026-1540HigApr 2, 2026
    risk 0.47cvss 7.2epss 0.01

    The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header

  • CVE-2026-35056HigApr 1, 2026
    risk 0.47cvss 7.2epss 0.01

    XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

  • CVE-2026-4998HigMar 28, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection.…

  • CVE-2026-4965HigMar 27, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the component Incomplete Fix CVE-2025-6101. Performing a manipulation results in improper neutralization of directives in dynamically…

  • CVE-2025-10679HigMar 23, 2026
    risk 0.47cvss 7.3epss 0.00

    The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input validation in the…

  • CVE-2026-32414HigMar 13, 2026
    risk 0.47cvss 7.2epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion.This issue affects Advanced Woo Labels: from n/a through <= 2.36.

  • CVE-2026-20892HigMar 11, 2026
    risk 0.47cvss 7.2epss 0.01

    Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privileges to execute arbitrary commands.

  • CVE-2026-3352HigMar 7, 2026
    risk 0.47cvss 7.2epss 0.00

    The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0.4 via the `update_wp_memory_constants()` method. This is due to insufficient input validation on the `wp_memory_limit` and `wp_max_memory_limit` settings…

  • CVE-2026-25887HigMar 6, 2026
    risk 0.47cvss 7.2epss 0.01

    Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB dataset Query. This issue has been patched in version 4.8.1.

  • CVE-2026-26699HigMar 2, 2026
    risk 0.47cvss 7.2epss 0.01

    sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.

  • CVE-2026-3409HigMar 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the file /api/v1/serve/awel/flow/import of the component Flow Import Endpoint. Performing a manipulation as part of File results in code…

  • CVE-2026-2296HigFeb 18, 2026
    risk 0.47cvss 7.2epss 0.01

    The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 3.1.0. This is due to insufficient input validation of the 'operator' field in conditional logic rules within the…

  • CVE-2025-70073HigFeb 5, 2026
    risk 0.47cvss 7.2epss 0.01

    An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function

  • CVE-2024-11976HigJan 23, 2026
    risk 0.47cvss 7.3epss 0.00

    The The BuddyPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 14.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2021-47778HigJan 21, 2026
    risk 0.47cvss 7.2epss 0.01

    GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code through plugin configuration parameters, leading to remote code execution on the server.

  • CVE-2022-50806HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific…

  • CVE-2021-47736HigDec 23, 2025
    risk 0.47cvss 7.2epss 0.01

    CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file…

  • CVE-2025-64676HigDec 18, 2025
    risk 0.47cvss 7.2epss 0.01

    '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

  • CVE-2025-67172HigDec 17, 2025
    risk 0.47cvss 7.2epss 0.01

    RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.