VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 171 of 353
  • CVE-2023-1003MedMar 7, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit has been disclosed…

  • CVE-2023-1005MedFeb 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.…

  • CVE-2023-1004MedFeb 24, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component WSH JScript Handler. The manipulation leads to code injection. Local access is required to approach this…

  • CVE-2021-4264MedDec 21, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be…

  • CVE-2020-36618MedDec 19, 2022
    risk 0.34cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Furqan node-whois. Affected is an unknown function of the file index.coffee. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). It is possible to launch the…

  • CVE-2022-24512MedMar 9, 2022
    risk 0.34cvss 6.3epss 0.02

    .NET and Visual Studio Remote Code Execution Vulnerability

  • CVE-2016-10072MedDec 27, 2016
    risk 0.34cvss 5.3epss 0.01

    WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this…

  • CVE-2010-5164MedAug 25, 2012
    risk 0.34cvss 5.3epss 0.00

    Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain…

  • CVE-2026-59894MedAug 17, 2026
    risk 0.33cvss epss 0.00

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted…

  • CVE-2026-73084MedAug 11, 2026
    risk 0.33cvss 6.1epss 0.00

    Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a…

  • CVE-2026-2830MedMar 6, 2026
    risk 0.33cvss 6.1epss 0.00

    The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output…

  • CVE-2026-2964MedFeb 23, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipulation leads to improperly controlled modification of object prototype…

  • CVE-2025-65026MedNov 19, 2025
    risk 0.33cvss 6.1epss 0.00

    esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Literal Injection vulnerability (CWE-94) in its CSS-to-JavaScript module conversion feature. When a CSS file is requested with the…

  • CVE-2025-9489MedSep 9, 2025
    risk 0.33cvss 5.0epss 0.00

    The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running…

  • CVE-2025-55305MedSep 4, 2025
    risk 0.33cvss 6.1epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource…

  • CVE-2025-5101MedAug 27, 2025
    risk 0.33cvss 5.0epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by…

  • CVE-2025-53626MedJul 10, 2025
    risk 0.33cvss 6.1epss 0.00

    pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.

  • CVE-2025-41365MedJun 6, 2025
    risk 0.33cvss epss 0.00

    Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing…

  • CVE-2025-3984MedApr 27, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java…

  • CVE-2024-51330MedNov 15, 2024
    risk 0.33cvss 5.1epss 0.00

    An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and…