VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 167 of 353
  • CVE-2026-23808MedMar 4, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor…

  • CVE-2026-1245MedJan 20, 2026
    risk 0.35cvss 6.5epss 0.01

    A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code execution when untrusted values are used in parser field names or encoding parameters. The library directly interpolates these values into dynamically generated…

  • CVE-2026-23733MedJan 18, 2026
    risk 0.35cvss 6.4epss 0.00

    LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to…

  • CVE-2025-68120MedDec 30, 2025
    risk 0.35cvss 5.4epss 0.00

    To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.

  • CVE-2025-14539MedDec 13, 2025
    risk 0.35cvss 5.4epss 0.00

    The The Shortcode Ajax plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…

  • CVE-2025-63693MedNov 18, 2025
    risk 0.35cvss 5.4epss 0.00

    The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows low-privilege attackers to construct comment content or…

  • CVE-2025-7711MedNov 17, 2025
    risk 0.35cvss 5.4epss 0.00

    The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.3. This is due to the software allowing users to execute an action that does not properly…

  • CVE-2025-8848MedOct 22, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the tag of the response.…

  • CVE-2025-42901MedOct 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no…

  • CVE-2025-58673MedSep 22, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12.

  • CVE-2025-8878MedAug 16, 2025
    risk 0.35cvss 6.5epss 0.00

    The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing…

  • CVE-2024-13814MedFeb 12, 2025
    risk 0.35cvss 5.4epss 0.01

    The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 9.1.5. This is due to the software allowing users to execute an action that does not properly validate a value before…

  • CVE-2024-10970MedJan 16, 2025
    risk 0.35cvss 5.4epss 0.00

    The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before…

  • CVE-2024-54997MedJan 10, 2025
    risk 0.35cvss 5.4epss 0.00

    MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.

  • CVE-2024-12417MedDec 13, 2024
    risk 0.35cvss 6.5epss 0.00

    The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode.…

  • CVE-2024-46965MedNov 11, 2024
    risk 0.35cvss 5.4epss 0.00

    The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.

  • CVE-2024-47158MedOct 25, 2024
    risk 0.35cvss 5.4epss 0.00

    N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the instructor's browser, or the instructor may be directed to a malicious website.

  • CVE-2023-39333MedSep 7, 2024
    risk 0.35cvss 5.3epss 0.01

    Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module. …

  • CVE-2024-41304MedJul 30, 2024
    risk 0.35cvss 5.4epss 0.00

    An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafted SVG file.

  • CVE-2024-37934MedJul 9, 2024
    risk 0.35cvss 5.4epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Injection.This issue affects Ninja Forms: from n/a through 3.8.4.