CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 309 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-13554 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name… | ||
| CVE-2026-13536 | Med | 0.00 | 4.3 | 0.00 | Jun 29, 2026 | A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may… | ||
| CVE-2026-13504 | Low | 0.00 | 3.5 | 0.00 | Jun 28, 2026 | A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit… | ||
| CVE-2026-13499 | Med | 0.00 | 4.3 | 0.00 | Jun 28, 2026 | A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The… | ||
| CVE-2026-53576 | Cri | 0.00 | 10.0 | 0.02 | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a… | ||
| CVE-2026-57315 | Hig | 0.00 | 8.5 | 0.00 | Jun 26, 2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions. | ||
| CVE-2025-7958 | Hig | 0.00 | — | 0.00 | Jun 26, 2026 | A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details. | ||
| CVE-2026-50741 | Hig | 0.00 | 8.8 | 0.04 | Jun 26, 2026 | Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method. | ||
| CVE-2026-55413 | Cri | 0.00 | — | 0.00 | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary… | ||
| CVE-2026-56049 | Hig | 0.00 | 8.5 | 0.00 | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. | ||
| CVE-2026-54823 | Cri | 0.00 | 9.9 | 0.01 | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. | ||
| CVE-2026-1606 | Med | 0.00 | 4.3 | 0.00 | Jun 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation. | ||
| CVE-2026-44959 | Hig | 0.00 | 8.8 | 0.00 | Jun 23, 2026 | A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed… | ||
| CVE-2026-34916 | Hig | 0.00 | 8.8 | 0.01 | Jun 23, 2026 | A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during… | ||
| CVE-2026-54816 | Hig | 0.00 | 7.5 | 0.00 | Jun 17, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21. | ||
| CVE-2026-29075 | Hig | 0.00 | 8.3 | 0.00 | Mar 6, 2026 | Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been… | ||
| CVE-2025-70341 | Hig | 0.00 | 7.8 | 0.00 | Mar 4, 2026 | Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files. | ||
| CVE-2026-25548 | Cri | 0.00 | 9.1 | 0.01 | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated… | ||
| CVE-2026-25227 | Cri | 0.00 | 9.1 | 0.01 | Feb 12, 2026 | authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the… | ||
| CVE-2026-25807 | Hig | 0.00 | 8.8 | 0.01 | Feb 9, 2026 | ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP socket on port 5757 without any authentication mechanism. Any remote attacker can connect to this… |
- risk 0.00cvss 4.3epss 0.00
A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of the component POST Request Handler. The manipulation of the argument Name…
- risk 0.00cvss 4.3epss 0.00
A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
- risk 0.00cvss 3.5epss 0.00
A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit…
- risk 0.00cvss 4.3epss 0.00
A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The…
- risk 0.00cvss 10.0epss 0.02
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a…
- risk 0.00cvss 8.5epss 0.00
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.
- risk 0.00cvss —epss 0.00
A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.
- risk 0.00cvss 8.8epss 0.04
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method.
- risk 0.00cvss —epss 0.00
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with builder role (free tier) can overwrite a globally-shared marketplace plugin with arbitrary…
- risk 0.00cvss 8.5epss 0.00
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
- risk 0.00cvss 9.9epss 0.01
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
- risk 0.00cvss 4.3epss 0.00
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.
- risk 0.00cvss 8.8epss 0.00
A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed…
- risk 0.00cvss 8.8epss 0.01
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during…
- risk 0.00cvss 7.5epss 0.00
Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.
- risk 0.00cvss 8.3epss 0.00
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been…
- risk 0.00cvss 7.8epss 0.00
Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.
- risk 0.00cvss 9.1epss 0.01
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated…
- risk 0.00cvss 9.1epss 0.01
authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the…
- risk 0.00cvss 8.8epss 0.01
ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, the P2P terminal sharing feature (share start) opens a TCP socket on port 5757 without any authentication mechanism. Any remote attacker can connect to this…