CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 303 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66748 | Hig | 0.00 | 8.8 | 0.01 | Jul 28, 2026 | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers… | ||
| CVE-2026-65880 | Cri | 0.00 | — | 0.00 | Jul 28, 2026 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type. | ||
| CVE-2026-14289 | Cri | 0.00 | 9.0 | 0.00 | Jul 27, 2026 | The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write… | ||
| CVE-2026-65693 | Hig | 0.00 | 7.2 | 0.00 | Jul 24, 2026 | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in… | ||
| CVE-2026-16801 | Hig | 0.00 | 8.8 | 0.00 | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not… | ||
| CVE-2026-16800 | Hig | 0.00 | 8.8 | 0.00 | Jul 24, 2026 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names… | ||
| CVE-2026-65907 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | ||
| CVE-2026-64815 | Hig | 0.00 | 8.1 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | ||
| CVE-2026-64803 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK | ||
| CVE-2026-64802 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration | ||
| CVE-2026-59543 | Cri | 0.00 | 9.9 | 0.01 | Jul 23, 2026 | Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | ||
| CVE-2026-15011 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation.… | ||
| CVE-2026-16606 | Cri | 0.00 | 9.8 | 0.01 | Jul 22, 2026 | A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally… | ||
| CVE-2026-16486 | Med | 0.00 | 4.3 | 0.00 | Jul 21, 2026 | A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made… | ||
| CVE-2026-16485 | Med | 0.00 | 4.3 | 0.00 | Jul 21, 2026 | A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The… | ||
| CVE-2026-65008 | Cri | 0.00 | 9.8 | 0.01 | Jul 21, 2026 | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because… | ||
| CVE-2026-52656 | Cri | 0.00 | 9.8 | 0.01 | Jul 20, 2026 | An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file | ||
| CVE-2026-51385 | Med | 0.00 | 6.9 | 0.00 | Jul 20, 2026 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions. | ||
| CVE-2026-60026 | Hig | 0.00 | — | 0.00 | Jul 20, 2026 | Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in… | ||
| CVE-2026-27823 | Hig | 0.00 | — | 0.01 | Jul 20, 2026 | A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior… |
- risk 0.00cvss 8.8epss 0.01
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers…
- risk 0.00cvss —epss 0.00
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
- risk 0.00cvss 9.0epss 0.00
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write…
- risk 0.00cvss 7.2epss 0.00
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in…
- risk 0.00cvss 8.8epss 0.00
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not…
- risk 0.00cvss 8.8epss 0.00
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names…
- risk 0.00cvss 9.1epss 0.00
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
- risk 0.00cvss 8.1epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
- risk 0.00cvss 7.8epss 0.00
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
- risk 0.00cvss 7.8epss 0.00
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
- risk 0.00cvss 9.9epss 0.01
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
- risk 0.00cvss 9.8epss 0.00
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation.…
- risk 0.00cvss 9.8epss 0.01
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made…
- risk 0.00cvss 4.3epss 0.00
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The…
- risk 0.00cvss 9.8epss 0.01
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because…
- risk 0.00cvss 9.8epss 0.01
An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file
- risk 0.00cvss 6.9epss 0.00
An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions.
- risk 0.00cvss —epss 0.00
Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in…
- risk 0.00cvss —epss 0.01
A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior…