VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 303 of 350
  • CVE-2026-66748HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.01

    Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers…

  • CVE-2026-65880CriJul 28, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.

  • CVE-2026-14289CriJul 27, 2026
    risk 0.00cvss 9.0epss 0.00

    The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write…

  • CVE-2026-65693HigJul 24, 2026
    risk 0.00cvss 7.2epss 0.00

    Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in…

  • CVE-2026-16801HigJul 24, 2026
    risk 0.00cvss 8.8epss 0.00

    Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not…

  • CVE-2026-16800HigJul 24, 2026
    risk 0.00cvss 8.8epss 0.00

    Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names…

  • CVE-2026-65907CriJul 23, 2026
    risk 0.00cvss 9.1epss 0.00

    In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

  • CVE-2026-64815HigJul 23, 2026
    risk 0.00cvss 8.1epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

  • CVE-2026-64803HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

  • CVE-2026-64802HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

  • CVE-2026-59543CriJul 23, 2026
    risk 0.00cvss 9.9epss 0.01

    Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

  • CVE-2026-15011CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation.…

  • CVE-2026-16606CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.01

    A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally…

  • CVE-2026-16486MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made…

  • CVE-2026-16485MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The…

  • CVE-2026-65008CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because…

  • CVE-2026-52656CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file

  • CVE-2026-51385MedJul 20, 2026
    risk 0.00cvss 6.9epss 0.00

    An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions.

  • CVE-2026-60026HigJul 20, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated PHP code execution. Authenticated builder user (core.create/core.edit) could inject PHP tags in…

  • CVE-2026-27823HigJul 20, 2026
    risk 0.00cvss epss 0.01

    A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior…