VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 170 of 353
  • CVE-2025-47562MedMay 16, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg allows Code Injection.This issue affects MapSVG: from n/a through <= 8.5.34.

  • CVE-2025-4767MedMay 16, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in defog-ai introspect up to 0.1.4. It has been rated as critical. Affected by this issue is the function test_custom_tool of the file introspect/backend/integration_routes.py of the component Test Endpoint. The manipulation of the argument input_model…

  • CVE-2025-47271MedMay 12, 2025
    risk 0.34cvss epss 0.00

    The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In versions 1.13.2 through 1.13.5, potentially untrusted data flows into PR creation logic. A malicious actor could construct a branch…

  • CVE-2025-47481MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Code Injection.This issue affects GS Testimonial Slider: from n/a through <= 3.2.9.

  • CVE-2025-4261MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as critical. This affects the function run_single of the file factool/factool/math/tool.py. The manipulation leads to code injection. The attack needs to be…

  • CVE-2025-4218MedMay 2, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulnerability is the function GPTSeleniumAgent of the file browserpilot/browserpilot/agents/gpt_selenium_agent.py. The manipulation of the argument instructions…

  • CVE-2025-3163MedApr 3, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possible to launch the attack on the local…

  • CVE-2023-51320MedFeb 20, 2025
    risk 0.34cvss 5.3epss 0.01

    PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used…

  • CVE-2024-13187MedJan 8, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TCC Handler. The manipulation leads to code injection. It is possible to launch the attack on the local…

  • CVE-2023-6604MedJan 6, 2025
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.

  • CVE-2024-12952MedDec 26, 2024
    risk 0.34cvss 6.3epss 0.01

    A vulnerability classified as critical was found in melMass comfy_mtb up to 0.1.4. Affected by this vulnerability is the function run_command of the file comfy_mtb/endpoint.py of the component Dependency Handler. The manipulation leads to code injection. The attack can be…

  • CVE-2024-11012MedDec 13, 2024
    risk 0.34cvss 6.3epss 0.00

    The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via njt_nofi_text AJAX action in all versions up to, and including, 2.1.4. This is due to the software allowing users to execute an action that does not…

  • CVE-2024-55918MedDec 13, 2024
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead to HTML injection by an attacker who can create a file in the current working directory.

  • CVE-2024-10909MedDec 6, 2024
    risk 0.34cvss 6.3epss 0.00

    The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX action in all versions up to, and including, 1.4.7. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2024-10681MedDec 6, 2024
    risk 0.34cvss 6.3epss 0.00

    The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.0.51. This is due to the software allowing users to execute an…

  • CVE-2024-11002MedNov 26, 2024
    risk 0.34cvss 6.3epss 0.01

    The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_shortcode_template AJAX action in all versions up to, and including, 2.1.4.2. This is due to the software allowing users to execute an action that does not…

  • CVE-2024-10262MedNov 16, 2024
    risk 0.34cvss 6.3epss 0.01

    The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This…

  • CVE-2024-8760MedOct 12, 2024
    risk 0.34cvss 5.3epss 0.00

    The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers to embed untrusted style information into comments resulting in a possibility of…

  • CVE-2023-31296MedDec 29, 2023
    risk 0.34cvss 5.3epss 0.00

    CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.

  • CVE-2023-1761MedMar 31, 2023
    risk 0.34cvss 6.3epss 0.00

    Cross-site Scripting in GitHub repository thorsten/phpmyfaq prior to 3.1.12.