VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,061)

page 180 of 354
  • CVE-2026-5319MedApr 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2026-5255MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in cross site scripting. The attack may be launched remotely.…

  • CVE-2026-5240MedApr 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads to cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2026-5157MedMar 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the argument cust_id leads to cross site scripting. The attack may be performed from…

  • CVE-2026-5015MedMar 28, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /logs of the component Endpoint. This manipulation of the argument filename causes cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2026-4992MedMar 27, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed…

  • CVE-2026-4898MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /dbfood/contact.php. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2026-4877MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2026-4849MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component Parameter Handler. The manipulation of the argument firstName leads to cross site scripting. The attack may be initiated remotely.…

  • CVE-2026-4848MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/extend/list.html. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be launched remotely. The exploit has been…

  • CVE-2026-4847MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /admin/config/list.html. Performing a manipulation of the argument Name results in cross site scripting. The attack can be initiated remotely. The exploit has…

  • CVE-2026-4846MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the file channel/admin.Account/autoReply.html. Such manipulation of the argument keyword leads to cross site scripting. It is possible to launch the attack remotely.…

  • CVE-2026-4845MedMar 26, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/index.html. This manipulation of the argument Search causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published…

  • CVE-2026-4557MedMar 22, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in cross site scripting. The attack may be initiated remotely. The exploit is now…

  • CVE-2026-3993MedMar 12, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unknown code of the file /manage_employee_deductions.php. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely.…

  • CVE-2026-3990MedMar 12, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in CesiumGS CesiumJS up to 1.137.0. Affected by this issue is some unknown functionality of the file Apps/Sandcastle/standalone.html. The manipulation of the argument c results in cross site scripting. The attack can be launched remotely. The…

  • CVE-2026-3982MedMar 12, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in itsourcecode University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_result.php. Executing a manipulation of the argument vr can lead to cross site scripting. The attack can be executed…

  • CVE-2026-3962MedMar 11, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the…

  • CVE-2026-3951MedMar 11, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of the file source-code/Locker-master/Ops/registry.js of the component Error Response Handler. The manipulation of the argument ID results in cross site…

  • CVE-2026-3812MedMar 9, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the file /manage_employee_allowances.php. This manipulation of the argument ID causes cross site scripting. The attack is possible to be carried out remotely. The…