VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,047)

page 179 of 353
  • CVE-2026-5825MedApr 9, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /delmemberinfo.php. Performing a manipulation of the argument userid results in cross site scripting. The attack can be initiated remotely. The exploit is…

  • CVE-2026-5705MedApr 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is…

  • CVE-2026-5671MedApr 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Impacted is an unknown function of the file /admin/class%20schedule/delete_batch.php of the component Class Schedule Deletion Endpoint. Executing a manipulation…

  • CVE-2026-5542MedApr 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in code-projects Simple Laundry System 1.0. Impacted is an unknown function of the file /modstaffinfo.php of the component Parameter Handler. Executing a manipulation of the argument userid can lead to cross site scripting. The attack may be…

  • CVE-2026-5541MedApr 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /modmemberinfo.php of the component Parameter Handler. Performing a manipulation of the argument userid results in cross site scripting. The attack may be…

  • CVE-2026-5539MedApr 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /modifymember.php of the component Parameter Handler. This manipulation of the argument firstName causes cross site scripting. The attack can be initiated remotely. The…

  • CVE-2026-5533MedApr 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in badlogic pi-mono 0.58.4. The impacted element is an unknown function of the file packages/web-ui/src/tools/artifacts/SvgArtifact.ts of the component SVG Artifact Handler. This manipulation causes cross site scripting. Remote exploitation of the…

  • CVE-2026-5319MedApr 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2026-5255MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in cross site scripting. The attack may be launched remotely.…

  • CVE-2026-5240MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads to cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2026-5157MedMar 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the argument cust_id leads to cross site scripting. The attack may be performed from…

  • CVE-2026-5015MedMar 28, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /logs of the component Endpoint. This manipulation of the argument filename causes cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2026-4992MedMar 27, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed…

  • CVE-2026-4898MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /dbfood/contact.php. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2026-4877MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2026-4849MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component Parameter Handler. The manipulation of the argument firstName leads to cross site scripting. The attack may be initiated remotely.…

  • CVE-2026-4848MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/extend/list.html. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be launched remotely. The exploit has been…

  • CVE-2026-4847MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /admin/config/list.html. Performing a manipulation of the argument Name results in cross site scripting. The attack can be initiated remotely. The exploit has…

  • CVE-2026-4846MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the file channel/admin.Account/autoReply.html. Such manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack remotely.…

  • CVE-2026-4845MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/index.html. This manipulation of the argument Search causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published…