VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,061)

page 191 of 354
  • CVE-2026-7580MedMay 1, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attacking locally is a requirement. Upgrading…

  • CVE-2026-24806MedJan 27, 2026
    risk 0.27cvss epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java. This…

  • CVE-2025-1465MedFeb 19, 2025
    risk 0.27cvss 4.1epss 0.01

    A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an…

  • CVE-2024-3958MedAug 8, 2024
    risk 0.27cvss 5.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social…

  • CVE-2023-22381MedMar 2, 2023
    risk 0.27cvss 4.1epss 0.01

    A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need…

  • CVE-2022-37396MedAug 3, 2022
    risk 0.27cvss 4.1epss 0.00

    In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution

  • CVE-2021-43221MedNov 24, 2021
    risk 0.27cvss 4.2epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2026-9568MedMay 26, 2026
    risk 0.26cvss 5.0epss 0.00

    A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. This manipulation causes code injection. It is possible to initiate the attack…

  • CVE-2026-39881MedApr 8, 2026
    risk 0.26cvss 5.0epss 0.01

    Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and…

  • CVE-2024-14020MedJan 7, 2026
    risk 0.26cvss 5.0epss 0.00

    A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improperly controlled modification of object…

  • CVE-2025-62416MedOct 16, 2025
    risk 0.26cvss 5.1epss 0.00

    Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with…

  • CVE-2025-10370LowSep 13, 2025
    risk 0.26cvss 3.5epss 0.01

    A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely.…

  • CVE-2025-8191LowJul 26, 2025
    risk 0.26cvss 3.5epss 0.02

    A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. It is…

  • CVE-2024-56803MedDec 31, 2024
    risk 0.26cvss epss 0.01

    Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file…

  • CVE-2024-10073MedOct 17, 2024
    risk 0.26cvss 5.0epss 0.01

    A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack…

  • CVE-2022-33725MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system privilege.

  • CVE-2021-32822MedAug 16, 2021
    risk 0.26cvss 4.0epss 0.01

    The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine configuration options through…

  • CVE-2025-58827LowSep 5, 2025
    risk 0.25cvss 3.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.

  • CVE-2024-53382MedMar 3, 2025
    risk 0.25cvss 4.9epss 0.00

    Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.

  • CVE-2022-37009LowJul 28, 2022
    risk 0.25cvss 3.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible