VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 17 of 349
  • CVE-2026-25366CriMar 25, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.

  • CVE-2026-26833CriMar 25, 2026
    risk 0.64cvss 9.8epss 0.02

    thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

  • CVE-2026-26831CriMar 25, 2026
    risk 0.64cvss 9.8epss 0.02

    textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and…

  • CVE-2026-26830CriMar 25, 2026
    risk 0.64cvss 9.8epss 0.02

    pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are…

  • CVE-2024-44722CriMar 20, 2026
    risk 0.64cvss 9.8epss 0.01

    SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.

  • CVE-2026-30694CriMar 19, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

  • CVE-2025-67113CriMar 19, 2026
    risk 0.64cvss 9.8epss 0.01

    OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary commands as root via a crafted TR-069 Download URL that is…

  • CVE-2026-30402CriMar 19, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function

  • CVE-2025-69902CriMar 16, 2026
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

  • CVE-2026-21669CriMar 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

  • CVE-2019-25468CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.01

    NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST requests with shell commands embedded in…

  • CVE-2025-67035CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such…

  • CVE-2026-30741CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack.

  • CVE-2026-30887CriMar 10, 2026
    risk 0.64cvss 9.9epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this untrusted user code inside the insecure…

  • CVE-2026-22390CriMar 5, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Code Injection.This issue affects Builderall Builder for WordPress: from n/a through <= 3.0.1.

  • CVE-2025-59059CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

  • CVE-2026-24105CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.

  • CVE-2026-26720CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

  • CVE-2026-24107CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`, may lead to critical command injection vulnerabilities.

  • CVE-2026-21658CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which…