VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,047)

page 172 of 353
  • CVE-2025-3984MedApr 27, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java…

  • CVE-2024-51330MedNov 15, 2024
    risk 0.33cvss 5.1epss 0.00

    An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and…

  • CVE-2024-29991MedApr 19, 2024
    risk 0.33cvss 5.0epss 0.01

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2023-7148MedDec 29, 2023
    risk 0.33cvss 5.0epss 0.01

    A vulnerability has been found in ShifuML shifu 0.12.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file src/main/java/ml/shifu/shifu/core/DataPurifier.java of the component Java Expression Language Handler. The manipulation of…

  • CVE-2022-47896MedDec 22, 2022
    risk 0.33cvss 5.0epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.

  • CVE-2022-23474MedDec 15, 2022
    risk 0.33cvss 6.1epss 0.01

    Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0.

  • CVE-2022-3869MedNov 5, 2022
    risk 0.33cvss 6.1epss 0.01

    Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.

  • CVE-2022-3245MedSep 20, 2022
    risk 0.33cvss 6.1epss 0.01

    HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.

  • CVE-2022-3242MedSep 20, 2022
    risk 0.33cvss 6.1epss 0.01

    Code Injection in GitHub repository microweber/microweber prior to 1.3.2.

  • CVE-2019-3652MedOct 9, 2019
    risk 0.33cvss 5.0epss 0.00

    Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.

  • CVE-2017-1002152MedJan 10, 2019
    risk 0.33cvss 6.1epss 0.01

    Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.

  • CVE-2014-10065MedMay 31, 2018
    risk 0.33cvss 6.1epss 0.01

    Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content.

  • CVE-2017-14077MedNov 18, 2017
    risk 0.33cvss 6.1epss 0.01

    HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or example_form.php.

  • CVE-2026-42396MedMay 21, 2026
    risk 0.32cvss 4.9epss 0.00

    Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

  • CVE-2026-25125MedApr 14, 2026
    risk 0.32cvss 4.9epss 0.00

    October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable…

  • CVE-2024-32499MedApr 28, 2025
    risk 0.32cvss 4.9epss 0.00

    Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.

  • CVE-2023-42404MedApr 28, 2025
    risk 0.32cvss 4.9epss 0.00

    OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.

  • CVE-2024-53386MedMar 3, 2025
    risk 0.32cvss 4.9epss 0.00

    Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

  • CVE-2023-44381MedDec 1, 2023
    risk 0.32cvss 4.9epss 0.01

    October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be…

  • CVE-2023-0888MedMar 13, 2023
    risk 0.32cvss 4.9epss 0.01

    An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. An authenticated user, having access to both…