VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 150 of 353
  • CVE-2025-0618MedApr 23, 2025
    risk 0.42cvss 6.5epss 0.01

    A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protection event to the HX service to trigger an exception. This exception will prevent any further tamper protection events from being…

  • CVE-2025-3472MedApr 22, 2025
    risk 0.42cvss 6.5epss 0.02

    The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2025-26996MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.0.1.

  • CVE-2024-13557MedMar 29, 2025
    risk 0.42cvss 6.5epss 0.00

    The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.1.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.…

  • CVE-2025-29806MedMar 23, 2025
    risk 0.42cvss 6.5epss 0.01

    No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2025-26924MedMar 15, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Ohio Extra: from n/a through <= 3.4.7.

  • CVE-2024-13815MedMar 5, 2025
    risk 0.42cvss 6.5epss 0.00

    The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it…

  • CVE-2025-26182MedMar 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file

  • CVE-2024-13806MedMar 1, 2025
    risk 0.42cvss 6.5epss 0.00

    The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…

  • CVE-2025-25507MedFeb 21, 2025
    risk 0.42cvss 6.5epss 0.01

    There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.

  • CVE-2023-51331MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.01

    PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…

  • CVE-2023-51324MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…

  • CVE-2023-51317MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.

  • CVE-2024-12415MedJan 31, 2025
    risk 0.42cvss 6.5epss 0.00

    The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.9.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This…

  • CVE-2024-40673MedJan 28, 2025
    risk 0.42cvss 6.5epss 0.00

    In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not…

  • CVE-2025-0060MedJan 14, 2025
    risk 0.42cvss 6.5epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as…

  • CVE-2024-54999MedJan 13, 2025
    risk 0.42cvss 6.5epss 0.00

    MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.

  • CVE-2024-12419MedJan 7, 2025
    risk 0.42cvss 6.5epss 0.00

    The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.0. This is due to the software allowing users to execute an action that does not properly…

  • CVE-2024-12421MedDec 13, 2024
    risk 0.42cvss 6.5epss 0.00

    The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.16.7.1. This is due to the software allowing users to execute an action that does not properly validate a…

  • CVE-2024-12420MedDec 13, 2024
    risk 0.42cvss 6.5epss 0.00

    The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 11.52. This is due to the software allowing users to execute an action that does not properly validate a value…