VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,061)

page 195 of 354
  • CVE-2026-4239LowMar 16, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit…

  • CVE-2026-4186LowMar 16, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in UEditor up to 1.4.3.2. This issue affects some unknown processing of the file php/controller.php?action=uploadimage of the component JSONP Callback Handler. This manipulation of the argument callback causes cross site scripting. The attack can…

  • CVE-2026-4166LowMar 16, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in cross site scripting. The attack can be launched remotely. The exploit has been…

  • CVE-2026-3984LowMar 12, 2026
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate…

  • CVE-2026-3983LowMar 12, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from…

  • CVE-2026-3946LowMar 11, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-ask. Performing a manipulation of the argument askcontent results in cross site scripting. The attack is possible to be carried out remotely. The exploit is…

  • CVE-2026-3819LowMar 9, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown function of the file /?page=manage_reservation of the component Reservation Management Module. Such manipulation of the argument ID leads to cross site scripting.…

  • CVE-2026-3766LowMar 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the argument fullname results in cross site scripting. The attack may be initiated…

  • CVE-2026-3743LowMar 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-3742LowMar 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument Title results in cross site scripting. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-3741LowMar 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads to cross site scripting. The attack may be performed from remote. The exploit…

  • CVE-2026-3721LowMar 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/helpdoc/domain/form/HelpDocAddForm.java of the component Help Documentation Module. This…

  • CVE-2026-3720LowMar 8, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript/src/views/business/oa/notice/components/notice-form-drawer.vue of the component Notice Module. The manipulation results in cross…

  • CVE-2026-3171LowFeb 25, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /queue.php. This manipulation of the argument firstname/lastname causes cross site scripting. The…

  • CVE-2026-3050LowFeb 24, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in horilla-opensource horilla up to 1.0.2. Impacted is an unknown function of the file static/assets/js/global.js of the component Leads Module. This manipulation of the argument Notes causes cross site scripting. The attack is possible to be carried out…

  • CVE-2026-2947LowFeb 22, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java of the component User Profile Handler. The manipulation results in cross site scripting. The…

  • CVE-2026-2946LowFeb 22, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/util/XssUtils.java of the component Article Content/Comments/Portfolio. The manipulation leads to…

  • CVE-2025-15583LowFeb 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in detronetdip E-commerce 1.0.0. This affects the function get_safe_value of the file utility/function.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the…

  • CVE-2026-2825LowFeb 20, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file tools/fix.py of the component Article Module. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2026-2622LowFeb 17, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blossom-backend/backend/src/main/java/com/blossom/backend/server/article/draft/ArticleController.java of the component Article Title Handler. The manipulation…