VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 149 of 353
  • CVE-2026-35086MedMay 19, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

  • CVE-2026-39052MedMay 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled script expressions through the underlying script engine without sandboxing or…

  • CVE-2025-15463MedMay 12, 2026
    risk 0.42cvss 6.5epss 0.00

    The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running…

  • CVE-2026-39087MedApr 23, 2026
    risk 0.42cvss 6.4epss 0.00

    ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.

  • CVE-2026-2582MedApr 14, 2026
    risk 0.42cvss 6.5epss 0.00

    The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a…

  • CVE-2026-3309MedApr 4, 2026
    risk 0.42cvss 6.5epss 0.00

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing…

  • CVE-2026-34202HigMar 31, 2026
    risk 0.42cvss 7.5epss 0.01

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a…

  • CVE-2026-4004MedMar 21, 2026
    risk 0.42cvss 6.5epss 0.00

    The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks in the callback_search() function and insufficient input validation that allows…

  • CVE-2026-33154HigMar 20, 2026
    risk 0.42cvss 7.5epss 0.01

    dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template…

  • CVE-2026-29039HigMar 6, 2026
    risk 0.42cvss 7.5epss 0.00

    changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as content filters via the include_filters field. These XPath expressions are processed using the…

  • CVE-2025-69262HigJan 7, 2026
    risk 0.42cvss 7.5epss 0.01

    pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could…

  • CVE-2025-60070MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This issue affects Molla: from n/a through <= 1.5.13.

  • CVE-2025-60068MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code Injection.This issue affects Javo Core: from n/a through <= 3.0.0.266.

  • CVE-2025-64320MedNov 4, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.

  • CVE-2025-10875MedNov 4, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Code Injection.This issue affects Mulesoft Anypoint Code Builder: before 1.11.6.

  • CVE-2025-57164MedOct 17, 2025
    risk 0.42cvss 6.5epss 0.01

    Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.

  • CVE-2025-54019MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through < 7.8.5.

  • CVE-2025-39483MedAug 14, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injection.This issue affects Eventer: from n/a through < 3.9.9.1.

  • CVE-2025-0134MedMay 14, 2025
    risk 0.42cvss epss 0.00

    A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.

  • CVE-2024-13812MedApr 26, 2025
    risk 0.42cvss 6.5epss 0.00

    The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.1.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This…