VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 307 of 350
  • CVE-2026-52200CriJul 8, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk

  • CVE-2026-35211MedJul 8, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script filter operator in its FilterOperator enum that allows any authenticated user with the KNOWLEDGE capability to pass…

  • CVE-2026-53951HigJul 8, 2026
    risk 0.00cvss epss 0.00

    Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_settings.py`) compares the template URL against a trusted prefix with a raw `str.startswith` and no path normalization, while the URL…

  • CVE-2026-55408HigJul 7, 2026
    risk 0.00cvss epss 0.00

    Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendered with unsanitized innerHTML.…

  • CVE-2026-53751HigJul 7, 2026
    risk 0.00cvss epss 0.00

    DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with special Unicode characters whose case-conversion behavior differs between DataEase validation and H2 parsing, allowing attackers to…

  • CVE-2026-43921HigJul 6, 2026
    risk 0.00cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When configuration values are updated, string values are written into…

  • CVE-2026-57572CriJul 6, 2026
    risk 0.00cvss 10.0epss 0.01

    Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process…

  • CVE-2026-14791LowJul 6, 2026
    risk 0.00cvss 3.5epss 0.00

    A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site…

  • CVE-2026-14752LowJul 5, 2026
    risk 0.00cvss 3.5epss 0.00

    A security vulnerability has been detected in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This affects the function add_definition of the file application/PHP/objects/notes/add_into_dictionary.php. Such manipulation of the argument reference leads to…

  • CVE-2026-14749HigJul 5, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was identified in mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be. Impacted is the function eval of the file application/pages/imba_calculator/calculate.php. The manipulation of the argument mathematical_sentence leads to code injection. The…

  • CVE-2026-14722HigJul 5, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impacts an unknown function of the file src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts of the component Git Repository Import. The manipulation results in code injection. The attack may be…

  • CVE-2026-14704MedJul 5, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in stephen-kruger bluebox up to 4.5.12. Affected by this vulnerability is an unknown functionality. Performing a manipulation of the argument code results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made…

  • CVE-2026-14691MedJul 5, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_settings_info of the file classes/SystemSettings.php of the component Setting Handler. Such manipulation of the argument content[]…

  • CVE-2026-14656MedJul 4, 2026
    risk 0.00cvss 4.3epss 0.00

    A security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-14655LowJul 4, 2026
    risk 0.00cvss 2.4epss 0.00

    A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting. The attack may be performed from…

  • CVE-2026-11778MedJul 3, 2026
    risk 0.00cvss 5.4epss 0.00

    The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.2.14. This is due to the software allowing users to execute an action that does not…

  • CVE-2026-57624CriJul 2, 2026
    risk 0.00cvss 10.0epss 0.01

    Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.

  • CVE-2026-27436CriJul 2, 2026
    risk 0.00cvss 9.1epss 0.00

    Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.

  • CVE-2026-55794HigJul 2, 2026
    risk 0.00cvss epss 0.00

    Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authenticated RCE. The issue happens when a…

  • CVE-2026-14439CriJul 1, 2026
    risk 0.00cvss epss 0.01

    A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone file-manipulation operations that use user-supplied paths without validation, allowing an authenticated user with…