CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,047)
page 218 of 353| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-11070 | Low | 0.23 | 3.5 | 0.00 | Nov 11, 2024 | A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of the file /admin/cmsTagType/save of the component Tag Type Handler. The manipulation of the argument name leads to cross site… | ||
| CVE-2024-11050 | Low | 0.23 | 3.5 | 0.00 | Nov 10, 2024 | A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the file /language.php. The manipulation of the argument LangID/LangName/LangEName leads to cross site scripting.… | ||
| CVE-2024-47826 | Low | 0.23 | 3.5 | 0.00 | Oct 14, 2024 | eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML tags in the pages: "experiments.php" (show mode), "database.php" (show mode) or "search.php". It works by providing HTML… | ||
| CVE-2024-8411 | Low | 0.23 | 3.5 | 0.01 | Sep 4, 2024 | A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit… | ||
| CVE-2024-7218 | Low | 0.23 | 3.5 | 0.01 | Jul 30, 2024 | A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?action=save_student. Executing manipulation of the argument Name can lead to cross site scripting. The attack may be performed from… | ||
| CVE-2024-21832 | Low | 0.23 | 3.5 | 0.00 | Jul 9, 2024 | A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body. | ||
| CVE-2024-6006 | Low | 0.23 | 3.5 | 0.00 | Jun 15, 2024 | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The… | ||
| CVE-2024-6005 | Low | 0.23 | 3.5 | 0.00 | Jun 15, 2024 | A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Department Name leads to cross site scripting.… | ||
| CVE-2024-3931 | Low | 0.23 | 3.5 | 0.00 | Apr 18, 2024 | A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/roles/check.php of the component User Selector. The manipulation of the argument ID Number leads to cross site scripting.… | ||
| CVE-2024-1706 | Low | 0.23 | 3.5 | 0.00 | Feb 21, 2024 | A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. This manipulation with the input hi causes cross site scripting. Remote exploitation of the attack is possible. The… | ||
| CVE-2024-0325 | Low | 0.23 | 3.6 | 0.01 | Feb 1, 2024 | In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins. | ||
| CVE-2023-33229 | Low | 0.23 | 3.5 | 0.01 | Jul 26, 2023 | The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML. | ||
| CVE-2023-1030 | Low | 0.23 | 3.5 | 0.01 | Feb 24, 2023 | A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of… | ||
| CVE-2022-3721 | Med | 0.23 | 4.6 | 0.01 | Nov 4, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39. | ||
| CVE-2021-22204 | Med | 0.23 | 6.8 | 1.00 | KEV | Apr 23, 2021 | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image | |
| CVE-2025-54940 | Low | 0.22 | 3.4 | 0.00 | Aug 8, 2025 | An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered. | ||
| CVE-2024-3924 | Med | 0.22 | 4.4 | 0.00 | May 30, 2024 | A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a… | ||
| CVE-2019-16774 | Med | 0.22 | 4.4 | 0.01 | Dec 12, 2019 | In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. | ||
| CVE-2026-14634 | Med | 0.21 | 4.3 | 0.00 | Jul 4, 2026 | A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin… | ||
| CVE-2026-14633 | Med | 0.21 | 4.3 | 0.00 | Jul 4, 2026 | A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument… |
- risk 0.23cvss 3.5epss 0.00
A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of the file /admin/cmsTagType/save of the component Tag Type Handler. The manipulation of the argument name leads to cross site…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the file /language.php. The manipulation of the argument LangID/LangName/LangEName leads to cross site scripting.…
- risk 0.23cvss 3.5epss 0.00
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML tags in the pages: "experiments.php" (show mode), "database.php" (show mode) or "search.php". It works by providing HTML…
- risk 0.23cvss 3.5epss 0.01
A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit…
- risk 0.23cvss 3.5epss 0.01
A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?action=save_student. Executing manipulation of the argument Name can lead to cross site scripting. The attack may be performed from…
- risk 0.23cvss 3.5epss 0.00
A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.
- risk 0.23cvss 3.5epss 0.00
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Department Name leads to cross site scripting.…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/roles/check.php of the component User Selector. The manipulation of the argument ID Number leads to cross site scripting.…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. This manipulation with the input hi causes cross site scripting. Remote exploitation of the attack is possible. The…
- risk 0.23cvss 3.6epss 0.01
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.
- risk 0.23cvss 3.5epss 0.01
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML.
- risk 0.23cvss 3.5epss 0.01
A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of…
- risk 0.23cvss 4.6epss 0.01
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
- risk 0.23cvss 6.8epss 1.00
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
- risk 0.22cvss 3.4epss 0.00
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.
- risk 0.22cvss 4.4epss 0.00
A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a…
- risk 0.22cvss 4.4epss 0.01
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
- risk 0.21cvss 4.3epss 0.00
A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin…
- risk 0.21cvss 4.3epss 0.00
A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument…