CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,061)
page 191 of 354| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-7580 | Med | 0.27 | 5.3 | 0.00 | May 1, 2026 | A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attacking locally is a requirement. Upgrading… | ||
| CVE-2026-24806 | Med | 0.27 | — | 0.00 | Jan 27, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java. This… | ||
| CVE-2025-1465 | Med | 0.27 | 4.1 | 0.01 | Feb 19, 2025 | A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an… | ||
| CVE-2024-3958 | Med | 0.27 | 5.3 | 0.00 | Aug 8, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social… | ||
| CVE-2023-22381 | Med | 0.27 | 4.1 | 0.01 | Mar 2, 2023 | A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need… | ||
| CVE-2022-37396 | Med | 0.27 | 4.1 | 0.00 | Aug 3, 2022 | In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution | ||
| CVE-2021-43221 | Med | 0.27 | 4.2 | 0.01 | Nov 24, 2021 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2026-9568 | Med | 0.26 | 5.0 | 0.00 | May 26, 2026 | A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. This manipulation causes code injection. It is possible to initiate the attack… | ||
| CVE-2026-39881 | Med | 0.26 | 5.0 | 0.01 | Apr 8, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and… | ||
| CVE-2024-14020 | Med | 0.26 | 5.0 | 0.00 | Jan 7, 2026 | A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improperly controlled modification of object… | ||
| CVE-2025-62416 | Med | 0.26 | 5.1 | 0.00 | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with… | ||
| CVE-2025-10370 | Low | 0.26 | 3.5 | 0.01 | Sep 13, 2025 | A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely.… | ||
| CVE-2025-8191 | Low | 0.26 | 3.5 | 0.02 | Jul 26, 2025 | A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. It is… | ||
| CVE-2024-56803 | Med | 0.26 | — | 0.01 | Dec 31, 2024 | Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file… | ||
| CVE-2024-10073 | Med | 0.26 | 5.0 | 0.01 | Oct 17, 2024 | A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack… | ||
| CVE-2022-33725 | Med | 0.26 | 4.0 | 0.00 | Aug 5, 2022 | A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system privilege. | ||
| CVE-2021-32822 | Med | 0.26 | 4.0 | 0.01 | Aug 16, 2021 | The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine configuration options through… | ||
| CVE-2025-58827 | Low | 0.25 | 3.8 | 0.00 | Sep 5, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61. | ||
| CVE-2024-53382 | Med | 0.25 | 4.9 | 0.00 | Mar 3, 2025 | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements. | ||
| CVE-2022-37009 | Low | 0.25 | 3.9 | 0.00 | Jul 28, 2022 | In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible |
- risk 0.27cvss 5.3epss 0.00
A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attacking locally is a requirement. Upgrading…
- risk 0.27cvss —epss 0.00
Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/batik/ext/awt/image/codec/png modules). This vulnerability is associated with program files PNGImageEncoder.Java. This…
- risk 0.27cvss 4.1epss 0.01
A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an…
- risk 0.27cvss 5.3epss 0.00
An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social…
- risk 0.27cvss 4.1epss 0.01
A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need…
- risk 0.27cvss 4.1epss 0.00
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.26cvss 5.0epss 0.00
A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. This manipulation causes code injection. It is possible to initiate the attack…
- risk 0.26cvss 5.0epss 0.01
Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and…
- risk 0.26cvss 5.0epss 0.00
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improperly controlled modification of object…
- risk 0.26cvss 5.1epss 0.00
Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with…
- risk 0.26cvss 3.5epss 0.01
A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely.…
- risk 0.26cvss 3.5epss 0.02
A vulnerability, which was classified as problematic, was found in macrozheng mall up to 1.0.3. Affected is an unknown function of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting. It is…
- risk 0.26cvss —epss 0.01
Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file…
- risk 0.26cvss 5.0epss 0.01
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack…
- risk 0.26cvss 4.0epss 0.00
A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system privilege.
- risk 0.26cvss 4.0epss 0.01
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data with engine configuration options through…
- risk 0.25cvss 3.8epss 0.00
Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
- risk 0.25cvss 4.9epss 0.00
Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
- risk 0.25cvss 3.9epss 0.00
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible