VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 8 of 349
  • CVE-2025-54322CriDec 27, 2025
    risk 0.66cvss 10.0epss 0.15

    Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.

  • CVE-2025-13486CriDec 3, 2025
    risk 0.66cvss 9.8epss 0.74

    The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes…

  • CVE-2023-34990CriDec 18, 2024
    risk 0.66cvss 9.8epss 0.25

    A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

  • CVE-2024-42448CriDec 12, 2024
    risk 0.66cvss 9.9epss 0.20

    From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

  • CVE-2024-6386CriAug 21, 2024
    risk 0.66cvss 9.9epss 0.26

    The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated…

  • CVE-2024-39932CriJul 4, 2024
    risk 0.66cvss 9.9epss 0.17

    Gogs through 0.13.0 allows argument injection during the previewing of changes.

  • CVE-2024-4884CriJun 25, 2024
    risk 0.66cvss 9.8epss 0.24

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

  • CVE-2024-3408CriJun 6, 2024
    risk 0.66cvss 9.8epss 0.78

    man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if…

  • CVE-2024-29276CriApr 2, 2024
    risk 0.66cvss 9.8epss 0.33

    An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.

  • CVE-2023-36177CriJan 23, 2024
    risk 0.66cvss 9.8epss 0.27

    An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute arbitrary code and gain sensitive information via crafted request in JSON-RPC-API.

  • CVE-2023-6016CriNov 16, 2023
    risk 0.66cvss 9.8epss 0.31

    An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.

  • CVE-2023-46042CriOct 19, 2023
    risk 0.66cvss 9.8epss 0.23

    An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().

  • CVE-2022-4116CriNov 22, 2022
    risk 0.66cvss 9.8epss 0.33

    A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

  • CVE-2022-40871CriOct 12, 2022
    risk 0.66cvss 9.8epss 0.33

    Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

  • CVE-2022-32417CriJul 14, 2022
    risk 0.66cvss 9.8epss 0.34

    PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

  • CVE-2022-23642HigFeb 18, 2022
    risk 0.66cvss 8.8epss 0.74

    Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the…

  • CVE-2020-8243HigKEVSep 30, 2020
    risk 0.66cvss 7.2epss 0.91

    A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

  • CVE-2020-11546CriJul 14, 2020
    risk 0.66cvss 9.8epss 0.33

    SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

  • CVE-2017-7411HigOct 30, 2017
    risk 0.66cvss 8.8epss 0.67

    An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API…

  • CVE-2016-5734CriJul 3, 2016
    risk 0.66cvss 9.8epss 0.81

    phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated…