VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 238 of 353
  • CVE-2024-11130LowNov 12, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/msg.php. The manipulation of the argument keyword leads to cross site scripting. The attack may be launched remotely. The…

  • CVE-2024-6807LowJul 17, 2024
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sscdms/classes/Users.php?f=save of the component HTTP POST Request Handler. The…

  • CVE-2024-6344LowJun 26, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to cross site scripting. It is possible to…

  • CVE-2023-7101HigKEVDec 24, 2023
    risk 0.16cvss 7.8epss 0.17

    Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems…

  • CVE-2023-7035LowDec 21, 2023
    risk 0.16cvss 2.4epss 0.01

    A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file packages\standard\templates\post.php of the component Setting Handler. The manipulation of the argument sitename leads to cross site…

  • CVE-2022-36036LowAug 29, 2022
    risk 0.16cvss 3.6epss 0.00

    mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 and 2.0.0-rc1. Modify any mermaid code blocks with arbitrary code and it will execute when the component is loaded by MDXjs. This…

  • CVE-2025-23376LowApr 28, 2025
    risk 0.15cvss 2.3epss 0.00

    Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to…

  • CVE-2021-41527LowFeb 7, 2025
    risk 0.15cvss epss 0.00

    An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasn’t been completed.

  • CVE-2021-23358LowMar 29, 2021
    risk 0.15cvss 3.3epss 0.04

    The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

  • CVE-2026-78187LowAug 24, 2026
    risk 0.13cvss 3.1epss

    A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high complexity level is associated…

  • CVE-2026-27675LowApr 14, 2026
    risk 0.13cvss 2.0epss 0.00

    SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have…

  • CVE-2023-31044LowMar 3, 2026
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate…

  • CVE-2025-15454LowJan 5, 2026
    risk 0.13cvss 3.1epss 0.00

    A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file src/components/ArticleView/ContentRender.tsx of the component RSS Handler. The manipulation results in cross site scripting. The attack can be executed remotely.…

  • CVE-2025-14007LowDec 4, 2025
    risk 0.13cvss 2.0epss 0.00

    A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mobile of the component Domain Name Binding Page. The manipulation results in cross site scripting. The attack may be performed from…

  • CVE-2024-3995LowJun 28, 2024
    risk 0.13cvss epss 0.01

    In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.

  • CVE-2024-43425HigNov 7, 2024
    risk 0.10cvss 8.1epss 0.83

    A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

  • CVE-2013-1488Mar 8, 2013
    risk 0.10cvss epss 0.87

    The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as…

  • CVE-2010-0483Mar 3, 2010
    risk 0.10cvss epss 0.86

    vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3)…

  • CVE-2009-1429Apr 29, 2009
    risk 0.10cvss epss 0.88

    The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1…

  • CVE-2026-12202LowJun 15, 2026
    risk 0.09cvss 2.4epss 0.00

    A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulation of the argument CSS class name leads to cross site scripting. The attack may be launched remotely. The…