CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,061)
page 192 of 354| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-20896 | Low | 0.25 | 3.9 | 0.00 | Aug 1, 2019 | cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). | ||
| CVE-2026-15410 | Hig | 0.24 | 7.2 | 0.12 | KEV | Jul 14, 2026 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute… | |
| CVE-2026-41692 | Med | 0.24 | 4.7 | 0.00 | May 7, 2026 | i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation tokens inside src and href attribute values with the raw string returned by i18next.t(). The… | ||
| CVE-2025-59302 | Med | 0.24 | 4.7 | 0.00 | Nov 27, 2025 | In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * … | ||
| CVE-2025-8155 | Low | 0.24 | 3.5 | 0.14 | Jul 25, 2025 | A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vb.htm of the component Management Application. The manipulation of the argument paratest leads to cross site… | ||
| CVE-2023-5540 | Med | 0.24 | 4.7 | 0.02 | Nov 9, 2023 | A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers. | ||
| CVE-2023-5539 | Med | 0.24 | 4.7 | 0.02 | Nov 9, 2023 | A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers. | ||
| CVE-2022-2099 | Med | 0.24 | 4.8 | 0.01 | Jul 17, 2022 | The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles | ||
| CVE-2026-19922 | Low | 0.23 | 3.5 | 0.00 | Aug 16, 2026 | A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scripting. The attack can be initiated… | ||
| CVE-2026-19916 | Low | 0.23 | 3.5 | 0.00 | Aug 15, 2026 | A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is… | ||
| CVE-2026-19230 | Low | 0.23 | 3.5 | 0.00 | Aug 7, 2026 | A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comment Input Box. The manipulation of the argument content leads to cross site scripting. The attack may be… | ||
| CVE-2026-19209 | Low | 0.23 | 3.5 | 0.00 | Aug 7, 2026 | A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file /social/index.php?page=home. This manipulation of the argument Comment causes cross site scripting. The attack may be initiated remotely. The exploit has been… | ||
| CVE-2026-12130 | Low | 0.23 | 3.5 | 0.00 | Jun 12, 2026 | A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack… | ||
| CVE-2026-12129 | Low | 0.23 | 3.5 | 0.00 | Jun 12, 2026 | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting.… | ||
| CVE-2026-11534 | Low | 0.23 | 3.5 | 0.00 | Jun 8, 2026 | A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of the argument name/address/fname results in cross site scripting. It… | ||
| CVE-2026-11520 | Low | 0.23 | 3.5 | 0.00 | Jun 8, 2026 | A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available… | ||
| CVE-2026-10247 | Low | 0.23 | 3.5 | 0.00 | Jun 1, 2026 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The… | ||
| CVE-2026-10246 | Low | 0.23 | 3.5 | 0.00 | Jun 1, 2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site… | ||
| CVE-2026-10245 | Low | 0.23 | 3.5 | 0.00 | Jun 1, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack… | ||
| CVE-2026-10244 | Low | 0.23 | 3.5 | 0.00 | Jun 1, 2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross… |
- risk 0.25cvss 3.9epss 0.00
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
- risk 0.24cvss 7.2epss 0.12
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute…
- risk 0.24cvss 4.7epss 0.00
i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation tokens inside src and href attribute values with the raw string returned by i18next.t(). The…
- risk 0.24cvss 4.7epss 0.00
In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSelector * …
- risk 0.24cvss 3.5epss 0.14
A vulnerability has been found in D-Link DCS-6010L 1.15.03 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vb.htm of the component Management Application. The manipulation of the argument paratest leads to cross site…
- risk 0.24cvss 4.7epss 0.02
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
- risk 0.24cvss 4.7epss 0.02
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
- risk 0.24cvss 4.8epss 0.01
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
- risk 0.23cvss 3.5epss 0.00
A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scripting. The attack can be initiated…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comment Input Box. The manipulation of the argument content leads to cross site scripting. The attack may be…
- risk 0.23cvss 3.5epss 0.00
A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file /social/index.php?page=home. This manipulation of the argument Comment causes cross site scripting. The attack may be initiated remotely. The exploit has been…
- risk 0.23cvss 3.5epss 0.00
A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting.…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of the argument name/address/fname results in cross site scripting. It…
- risk 0.23cvss 3.5epss 0.00
A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of the argument generic_name results in cross site scripting. The…
- risk 0.23cvss 3.5epss 0.00
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of the argument medicine_presentation leads to cross site…
- risk 0.23cvss 3.5epss 0.00
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. Executing a manipulation of the argument company_name can lead to cross site scripting. The attack…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing a manipulation of the argument medicine_name results in cross…