VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,061)

page 194 of 354
  • CVE-2026-5806LowApr 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cross site scripting. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-5568LowApr 5, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Akaunting up to 3.1.21. This issue affects some unknown processing of the component Invoice/Billing. The manipulation of the argument notes leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-5468LowApr 3, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-5332LowApr 2, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of the component WAF Firewall. The manipulation of the argument param leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is…

  • CVE-2026-5325LowApr 2, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create Ticket. This manipulation of the argument Description causes cross site…

  • CVE-2026-5254LowApr 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component Webhook Handler. The manipulation leads to cross site scripting. The attack may…

  • CVE-2026-5253LowApr 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component editNotice Endpoint. Executing a manipulation can lead to cross site scripting. The…

  • CVE-2026-5252LowApr 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The…

  • CVE-2026-5249LowApr 1, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible…

  • CVE-2026-4995LowMar 28, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of the file frontend/public/annotator/index.html of the component Window Message Event Handler. This manipulation causes cross site scripting. The attack can be…

  • CVE-2026-4991LowMar 27, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The…

  • CVE-2026-4973LowMar 27, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulation of the argument quiz_question results in cross site scripting. It is possible…

  • CVE-2026-4969LowMar 27, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads to cross site scripting. Remote exploitation of the attack…

  • CVE-2026-4835LowMar 26, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting.…

  • CVE-2026-4626LowMar 24, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-4596LowMar 23, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. The manipulation of the argument first_Name leads to cross site scripting. The attack may be initiated remotely. The exploit is…

  • CVE-2026-4495LowMar 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/yiiu/pybbs/controller/api/CommentApiController.java. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2026-4494LowMar 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in atjiu pybbs 6.0.0. This affects the function create of the file src/main/java/co/yiiu/pybbs/controller/api/TopicApiController.java. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is…

  • CVE-2026-4355LowMar 18, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of the argument Name results in cross site scripting. The attack may be initiated…

  • CVE-2026-4354LowMar 18, 2026
    risk 0.23cvss 3.5epss 0.02

    A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 of the file apply_sec.cgi of the component Web Interface. Such manipulation of the argument Language leads to cross site scripting. It is possible to launch…