VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 166 of 353
  • CVE-2023-39593MedOct 17, 2024
    risk 0.36cvss 5.6epss 0.01

    Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

  • CVE-2024-8880MedSep 16, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.php?app=main&inc=core_auth&route=forgot&op=forgot of the component Template Handler. The manipulation of the argument…

  • CVE-2024-8864MedSep 15, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerability is the function Calculator of the file python/composio/tools/local/mathematical/actions/calculator.py. The manipulation leads to code injection. The…

  • CVE-2024-37900MedJul 31, 2024
    risk 0.36cvss 6.4epss 0.16

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into…

  • CVE-2023-35701MedMay 3, 2024
    risk 0.36cvss 6.6epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is running. The…

  • CVE-2024-1705MedFeb 21, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php of the component Installation. The manipulation leads to code injection. The attack may be…

  • CVE-2023-3665MedOct 4, 2023
    risk 0.36cvss 5.5epss 0.00

    A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.

  • CVE-2023-21569MedJun 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Azure DevOps Server Spoofing Vulnerability

  • CVE-2021-26277MedFeb 17, 2023
    risk 0.36cvss 5.6epss 0.00

    The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.

  • CVE-2022-41205MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application.

  • CVE-2021-25415MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.

  • CVE-2018-2418MedMay 9, 2018
    risk 0.36cvss 5.5epss 0.02

    SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

  • CVE-2026-18385MedAug 16, 2026
    risk 0.35cvss 5.4epss 0.00

    The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.19. This is due to the software allowing…

  • CVE-2025-13146MedJul 22, 2026
    risk 0.35cvss 6.5epss 0.00

    The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before…

  • CVE-2026-48192MedJun 30, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), Mendix Studio Pro 10.13 (All versions), Mendix Studio Pro 10.14 (All versions), Mendix Studio Pro 10.15 (All versions), Mendix Studio Pro 10.16 (All versions),…

  • CVE-2026-11157MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2026-45719MedMay 27, 2026
    risk 0.35cvss 6.5epss 0.00

    Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request body that is interpolated directly into a CouchDB reduce function definition without validation. Although an internal SCHEMA_MAP…

  • CVE-2026-8539MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Script injection in SanitizerAPI in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-12669MedMay 14, 2026
    risk 0.35cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject HTML and JavaScript into email notifications sent to other users due to improper…

  • CVE-2026-1509MedApr 15, 2026
    risk 0.35cvss 5.4epss 0.00

    The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up to, and including, 3.15.1. This is due to the plugin's `output_action_hook()` function accepting user-controlled input to trigger any registered WordPress…