VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (4,435)

page 47 of 222
  • CVE-2024-9837HigOct 15, 2024
    risk 0.41cvss 7.3epss 0.02

    The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before…

  • CVE-2024-8481HigSep 25, 2024
    risk 0.41cvss 7.3epss 0.02

    The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.4. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This…

  • CVE-2024-6950MedJul 21, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in Prain up to 1.3.0. Affected by this issue is some unknown functionality of the file /?import of the component HTTP POST Request Handler. The manipulation of the argument file leads to code injection. The attack…

  • CVE-2024-38990MedJul 1, 2024
    risk 0.41cvss 6.3epss 0.00

    Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39209MedJun 27, 2024
    risk 0.41cvss 6.3epss 0.00

    luci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.

  • CVE-2023-26877MedJun 26, 2024
    risk 0.41cvss 6.3epss 0.00

    File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.

  • CVE-2024-33335MedJun 20, 2024
    risk 0.41cvss 6.3epss 0.02

    SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.

  • CVE-2024-31974MedMay 17, 2024
    risk 0.41cvss 6.3epss 0.02

    The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and…

  • CVE-2024-30567MedApr 16, 2024
    risk 0.41cvss 6.3epss 0.03

    An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting functionality.

  • CVE-2025-51427HigMay 19, 2026
    risk 0.40cvss 7.3epss 0.00

    An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].

  • CVE-2026-31379MedMay 19, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects…

  • CVE-2026-43874HigMay 11, 2026
    risk 0.40cvss 7.2epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the YPTSocket autoEvalCodeOnHTML eval sink (from CVE-2026-40911) only strips the payload when it sits under $json['msg'], but the relay function msgToResourceId()…

  • CVE-2026-27674MedApr 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the…

  • CVE-2026-6110HigApr 12, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.py of the component Tree-of-Thought Solver. The manipulation leads to code injection. It is possible to initiate the attack…

  • CVE-2026-5970HigApr 9, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public…

  • CVE-2025-70844MedApr 7, 2026
    risk 0.40cvss 6.1epss 0.00

    yaffa v2.0.0 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript into the "Add Account Group" function on the account-group page, allowing execution of arbitrary script in the context of users who view the affected page.

  • CVE-2026-3395HigMar 1, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to…

  • CVE-2025-14541HigFeb 11, 2026
    risk 0.40cvss 7.2epss 0.00

    The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.22 via the conditional_tags parameter. This is due to the plugin using PHP's eval() function on user-controlled input without proper validation or…

  • CVE-2025-14509HigDec 30, 2025
    risk 0.40cvss 7.2epss 0.00

    The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13. This is due to the plugin using eval() to execute user-supplied input from the 'Conditional Tags' setting without proper…

  • CVE-2025-13592HigDec 29, 2025
    risk 0.40cvss 7.2epss 0.00

    The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 via the 'change-ad__content' shortcode parameter. This allows authenticated attackers with editor-level permissions or above, to execute code on the server.