VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 168 of 353
  • CVE-2024-4261MedMay 22, 2024
    risk 0.35cvss 5.4epss 0.00

    The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2024-3044MedMay 14, 2024
    risk 0.35cvss 6.5epss 0.01

    Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed…

  • CVE-2024-4144MedMay 14, 2024
    risk 0.35cvss 6.5epss 0.01

    The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the…

  • CVE-2024-28593MedMar 22, 2024
    risk 0.35cvss 5.4epss 0.01

    The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code, you can use it in your text to do…

  • CVE-2023-5800MedFeb 5, 2024
    risk 0.35cvss 5.4epss 0.01

    Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or…

  • CVE-2023-5550MedNov 9, 2023
    risk 0.35cvss 6.5epss 0.01

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

  • CVE-2023-0792MedFeb 12, 2023
    risk 0.35cvss 6.5epss 0.01

    Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2022-0578MedMay 16, 2022
    risk 0.35cvss 6.5epss 0.01

    Code Injection in GitHub repository publify/publify prior to 9.2.8.

  • CVE-2022-23008MedJan 25, 2022
    risk 0.35cvss 5.4epss 0.01

    On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances.…

  • CVE-2021-34801MedJun 16, 2021
    risk 0.35cvss 5.3epss 0.02

    Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.

  • CVE-2017-1753MedAug 20, 2018
    risk 0.35cvss 5.4epss 0.01

    Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655.

  • CVE-2018-1288MedJul 26, 2018
    risk 0.35cvss 5.4epss 0.05

    In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

  • CVE-2017-1329MedJul 6, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 126231.

  • CVE-2017-1248MedJul 6, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124628.

  • CVE-2017-1242MedJul 6, 2018
    risk 0.35cvss 5.4epss 0.01

    IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124524.

  • CVE-2017-3907MedJun 13, 2018
    risk 0.35cvss 5.4epss 0.02

    Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector.

  • CVE-2017-6782MedAug 17, 2017
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due to improper sanitization of parameter values by the…

  • CVE-2015-5970MedFeb 18, 2016
    risk 0.35cvss 5.3epss 0.01

    The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.

  • CVE-2010-5153MedAug 25, 2012
    risk 0.35cvss 5.3epss 0.01

    Race condition in Avira Premium Security Suite 10.0.0.536 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space…

  • CVE-2026-63187MedAug 19, 2026
    risk 0.34cvss 6.3epss 0.00

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's inline echo command before piping the title…