VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 128 of 350
  • CVE-2024-13793HigMay 8, 2025
    risk 0.47cvss 7.3epss 0.00

    The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.8.11. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2025-2802HigMay 6, 2025
    risk 0.47cvss 7.3epss 0.00

    The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.3.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2024-13738HigMay 3, 2025
    risk 0.47cvss 7.3epss 0.00

    The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2025-3491HigApr 26, 2025
    risk 0.47cvss 7.2epss 0.01

    The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'acpt_validate_setting' function. This is due to insufficient sanitization of the 'template_name' parameter.…

  • CVE-2025-2801HigApr 26, 2025
    risk 0.47cvss 7.3epss 0.01

    The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.4. This is due to the software allowing users to execute an action that does not…

  • CVE-2025-3509HigApr 17, 2025
    risk 0.47cvss 7.2epss 0.01

    A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromise. The vulnerability involves…

  • CVE-2025-29661HigApr 17, 2025
    risk 0.47cvss 7.2epss 0.00

    Litepubl CMS <= 7.0.9 is vulnerable to RCE in admin/service/run.

  • CVE-2025-29039HigApr 17, 2025
    risk 0.47cvss 7.2epss 0.01

    An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8

  • CVE-2025-32596HigApr 17, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Code Injection.This issue affects Real Estate Manager: from n/a through <= 7.3.

  • CVE-2024-50960HigApr 15, 2025
    risk 0.47cvss 7.2epss 0.02

    A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

  • CVE-2023-42875HigApr 11, 2025
    risk 0.47cvss 7.3epss 0.01

    Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling.

  • CVE-2025-2809HigApr 10, 2025
    risk 0.47cvss 7.3epss 0.00

    The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running…

  • CVE-2025-2805HigApr 10, 2025
    risk 0.47cvss 7.3epss 0.00

    The ORDER POST plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2025-2803HigMar 29, 2025
    risk 0.47cvss 7.3epss 0.00

    The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…

  • CVE-2024-54448HigMar 14, 2025
    risk 0.47cvss 7.2epss 0.00

    The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automation Scripting is needed to carry out the…

  • CVE-2025-2169HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.01

    The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.0.4. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2024-13890HigMar 8, 2025
    risk 0.47cvss 7.2epss 0.00

    The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP code to be entered by all users for whom unfiltered HTML is allowed. This makes it possible for authenticated attackers, with…

  • CVE-2025-1510HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.01

    The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. This is due to the software allowing users to execute an action that does not properly validate a value before running…

  • CVE-2025-1509HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.01

    The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This…

  • CVE-2024-13792HigFeb 20, 2025
    risk 0.47cvss 7.3epss 0.01

    The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly validate a value before…