VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,047)

page 218 of 353
  • CVE-2024-11070LowNov 11, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of the file /admin/cmsTagType/save of the component Tag Type Handler. The manipulation of the argument name leads to cross site…

  • CVE-2024-11050LowNov 10, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the file /language.php. The manipulation of the argument LangID/LangName/LangEName leads to cross site scripting.…

  • CVE-2024-47826LowOct 14, 2024
    risk 0.23cvss 3.5epss 0.00

    eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML tags in the pages: "experiments.php" (show mode), "database.php" (show mode) or "search.php". It works by providing HTML…

  • CVE-2024-8411LowSep 4, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument Sub_Expresion can lead to cross site scripting. It is possible to launch the attack remotely. The exploit…

  • CVE-2024-7218LowJul 30, 2024
    risk 0.23cvss 3.5epss 0.01

    A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?action=save_student. Executing manipulation of the argument Name can lead to cross site scripting. The attack may be performed from…

  • CVE-2024-21832LowJul 9, 2024
    risk 0.23cvss 3.5epss 0.00

    A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.

  • CVE-2024-6006LowJun 15, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The…

  • CVE-2024-6005LowJun 15, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Department Name leads to cross site scripting.…

  • CVE-2024-3931LowApr 18, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/roles/check.php of the component User Selector. The manipulation of the argument ID Number leads to cross site scripting.…

  • CVE-2024-1706LowFeb 21, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. This manipulation with the input hi causes cross site scripting. Remote exploitation of the attack is possible. The…

  • CVE-2024-0325LowFeb 1, 2024
    risk 0.23cvss 3.6epss 0.01

    In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.  

  • CVE-2023-33229LowJul 26, 2023
    risk 0.23cvss 3.5epss 0.01

    The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML.

  • CVE-2023-1030LowFeb 24, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST Parameter Handler. The manipulation of…

  • CVE-2022-3721MedNov 4, 2022
    risk 0.23cvss 4.6epss 0.01

    Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.

  • CVE-2021-22204MedKEVApr 23, 2021
    risk 0.23cvss 6.8epss 1.00

    Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image

  • CVE-2025-54940LowAug 8, 2025
    risk 0.22cvss 3.4epss 0.00

    An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.

  • CVE-2024-3924MedMay 30, 2024
    risk 0.22cvss 4.4epss 0.00

    A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a…

  • CVE-2019-16774MedDec 12, 2019
    risk 0.22cvss 4.4epss 0.01

    In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.

  • CVE-2026-14634MedJul 4, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin…

  • CVE-2026-14633MedJul 4, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument…