VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 156 of 353
  • CVE-2024-13487HigFeb 6, 2025
    risk 0.41cvss 7.3epss 0.01

    The The CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution via the get_products_price() function in all versions up to, and including, 2.2.5.…

  • CVE-2024-12238MedDec 29, 2024
    risk 0.41cvss 6.3epss 0.00

    The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.22. This is due to the software allowing users to execute an action that does not properly validate…

  • CVE-2024-12900MedDec 23, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File Handler. The manipulation of the argument database password leads to code injection. It is possible…

  • CVE-2024-12789MedDec 19, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely.…

  • CVE-2024-12350MedDec 9, 2024
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\com\cms\controller\admin\TemplateController.java of the component Template Handler. The manipulation of the argument content leads…

  • CVE-2024-11034HigNov 23, 2024
    risk 0.41cvss 7.3epss 0.01

    The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This…

  • CVE-2024-21541HigNov 13, 2024
    risk 0.41cvss 7.3epss 0.01

    Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are…

  • CVE-2024-10505MedOct 30, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2024-45200MedSep 30, 2024
    risk 0.41cvss 6.3epss 0.01

    In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer overflow upon deserialization of session information via a malformed browse-reply packet, aka KartLANPwn. The victim is not…

  • CVE-2024-9324MedSep 29, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Intelbras InControl up to 2.21.57. It has been rated as critical. Affected by this issue is some unknown functionality of the file /v1/operador/ of the component Relatório de Operadores Page. The manipulation of the argument fields leads to code…

  • CVE-2024-8481HigSep 25, 2024
    risk 0.41cvss 7.3epss 0.01

    The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.4. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This…

  • CVE-2024-6950MedJul 21, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in Prain up to 1.3.0. Affected by this issue is some unknown functionality of the file /?import of the component HTTP POST Request Handler. The manipulation of the argument file leads to code injection. The attack…

  • CVE-2024-39002MedJul 1, 2024
    risk 0.41cvss 6.3epss 0.01

    rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38990MedJul 1, 2024
    risk 0.41cvss 6.3epss 0.00

    Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39209MedJun 27, 2024
    risk 0.41cvss 6.3epss 0.01

    luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.

  • CVE-2023-26877MedJun 26, 2024
    risk 0.41cvss 6.3epss 0.00

    File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.

  • CVE-2024-33335MedJun 20, 2024
    risk 0.41cvss 6.3epss 0.01

    SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.

  • CVE-2024-31974MedMay 17, 2024
    risk 0.41cvss 6.3epss 0.01

    The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and…

  • CVE-2024-30567MedApr 16, 2024
    risk 0.41cvss 6.3epss 0.01

    An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting functionality.

  • CVE-2024-2209MedMar 27, 2024
    risk 0.41cvss 6.3epss 0.00

    A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary…