VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 129 of 350
  • CVE-2025-25944HigFeb 19, 2025
    risk 0.47cvss 7.3epss 0.00

    Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.

  • CVE-2024-13797HigFeb 18, 2025
    risk 0.47cvss 7.3epss 0.01

    The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2024-13345HigFeb 13, 2025
    risk 0.47cvss 7.3epss 0.01

    The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2024-13453HigJan 30, 2025
    risk 0.47cvss 7.3epss 0.01

    The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.6.0. This is due to the software allowing users to execute an action that does not properly validate a…

  • CVE-2025-23051HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.

  • CVE-2024-11733HigJan 3, 2025
    risk 0.47cvss 7.3epss 0.01

    The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.…

  • CVE-2024-10910HigDec 12, 2024
    risk 0.47cvss 7.3epss 0.01

    The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not…

  • CVE-2024-37862HigDec 5, 2024
    risk 0.47cvss 7.3epss 0.00

    Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process.

  • CVE-2024-37860HigDec 5, 2024
    risk 0.47cvss 7.3epss 0.00

    Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process

  • CVE-2024-11620HigNov 28, 2024
    risk 0.47cvss 7.2epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Code Injection.This issue affects Rank Math SEO: from n/a through <= 1.0.231.

  • CVE-2024-52959HigNov 27, 2024
    risk 0.47cvss 7.2epss 0.01

    A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

  • CVE-2024-53268HigNov 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fact that openExternal is used without any filtering of URI schemes to obtain remote code execution…

  • CVE-2024-10899HigNov 20, 2024
    risk 0.47cvss 7.3epss 0.01

    The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.6. This is due to the software allowing users to execute an action that does not properly validate a value before running…

  • CVE-2024-9839HigNov 16, 2024
    risk 0.47cvss 7.3epss 0.01

    The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…

  • CVE-2024-10640HigNov 9, 2024
    risk 0.47cvss 7.3epss 0.00

    The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.2. This is due to the software allowing users to execute an action that does not properly validate a…

  • CVE-2024-51243HigOct 30, 2024
    risk 0.47cvss 7.2epss 0.01

    The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.

  • CVE-2024-9846HigOct 30, 2024
    risk 0.47cvss 7.3epss 0.01

    The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.0. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2024-9162HigOct 28, 2024
    risk 0.47cvss 7.2epss 0.03

    The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with…

  • CVE-2024-37845HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.

  • CVE-2024-48700HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.