CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,047)
page 172 of 353| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-3984 | Med | 0.33 | 5.0 | 0.00 | Apr 27, 2025 | A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java… | ||
| CVE-2024-51330 | Med | 0.33 | 5.1 | 0.00 | Nov 15, 2024 | An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and… | ||
| CVE-2024-29991 | Med | 0.33 | 5.0 | 0.01 | Apr 19, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2023-7148 | Med | 0.33 | 5.0 | 0.01 | Dec 29, 2023 | A vulnerability has been found in ShifuML shifu 0.12.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file src/main/java/ml/shifu/shifu/core/DataPurifier.java of the component Java Expression Language Handler. The manipulation of… | ||
| CVE-2022-47896 | Med | 0.33 | 5.0 | 0.00 | Dec 22, 2022 | In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. | ||
| CVE-2022-23474 | Med | 0.33 | 6.1 | 0.01 | Dec 15, 2022 | Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0. | ||
| CVE-2022-3869 | Med | 0.33 | 6.1 | 0.01 | Nov 5, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2. | ||
| CVE-2022-3245 | Med | 0.33 | 6.1 | 0.01 | Sep 20, 2022 | HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input. | ||
| CVE-2022-3242 | Med | 0.33 | 6.1 | 0.01 | Sep 20, 2022 | Code Injection in GitHub repository microweber/microweber prior to 1.3.2. | ||
| CVE-2019-3652 | Med | 0.33 | 5.0 | 0.00 | Oct 9, 2019 | Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer. | ||
| CVE-2017-1002152 | Med | 0.33 | 6.1 | 0.01 | Jan 10, 2019 | Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles. | ||
| CVE-2014-10065 | Med | 0.33 | 6.1 | 0.01 | May 31, 2018 | Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content. | ||
| CVE-2017-14077 | Med | 0.33 | 6.1 | 0.01 | Nov 18, 2017 | HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or example_form.php. | ||
| CVE-2026-42396 | Med | 0.32 | 4.9 | 0.00 | May 21, 2026 | Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail | ||
| CVE-2026-25125 | Med | 0.32 | 4.9 | 0.00 | Apr 14, 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable… | ||
| CVE-2024-32499 | Med | 0.32 | 4.9 | 0.00 | Apr 28, 2025 | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. | ||
| CVE-2023-42404 | Med | 0.32 | 4.9 | 0.00 | Apr 28, 2025 | OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution. | ||
| CVE-2024-53386 | Med | 0.32 | 4.9 | 0.00 | Mar 3, 2025 | Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. | ||
| CVE-2023-44381 | Med | 0.32 | 4.9 | 0.01 | Dec 1, 2023 | October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be… | ||
| CVE-2023-0888 | Med | 0.32 | 4.9 | 0.01 | Mar 13, 2023 | An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. An authenticated user, having access to both… |
- risk 0.33cvss 5.0epss 0.00
A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\RegisteredServiceSimpleFormController.java…
- risk 0.33cvss 5.1epss 0.00
An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and…
- risk 0.33cvss 5.0epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.33cvss 5.0epss 0.01
A vulnerability has been found in ShifuML shifu 0.12.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file src/main/java/ml/shifu/shifu/core/DataPurifier.java of the component Java Expression Language Handler. The manipulation of…
- risk 0.33cvss 5.0epss 0.00
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
- risk 0.33cvss 6.1epss 0.01
Editor.js is a block-style editor with clean JSON output. Versions prior to 2.26.0 are vulnerable to Code Injection via pasted input. The processHTML method passes pasted input into wrapper’s innerHTML. This issue is patched in version 2.26.0.
- risk 0.33cvss 6.1epss 0.01
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
- risk 0.33cvss 6.1epss 0.01
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
- risk 0.33cvss 6.1epss 0.01
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
- risk 0.33cvss 5.0epss 0.00
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.
- risk 0.33cvss 6.1epss 0.01
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.
- risk 0.33cvss 6.1epss 0.01
Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content.
- risk 0.33cvss 6.1epss 0.01
HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or example_form.php.
- risk 0.32cvss 4.9epss 0.00
Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
- risk 0.32cvss 4.9epss 0.00
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable…
- risk 0.32cvss 4.9epss 0.00
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
- risk 0.32cvss 4.9epss 0.00
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
- risk 0.32cvss 4.9epss 0.00
Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
- risk 0.32cvss 4.9epss 0.01
October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be…
- risk 0.32cvss 4.9epss 0.01
An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. An authenticated user, having access to both…