CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,295)
page 9 of 365| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-7411 | Hig | 0.66 | 8.8 | 0.67 | Oct 30, 2017 | An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API… | ||
| CVE-2016-5734 | Cri | 0.66 | 9.8 | 0.81 | Jul 3, 2016 | phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated… | ||
| CVE-2016-1985 | Cri | 0.66 | 10.0 | 0.07 | Jan 30, 2016 | HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | ||
| CVE-2009-2512 | Cri | 0.66 | 9.8 | 0.31 | Nov 11, 2009 | The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka "Web Services… | ||
| CVE-2026-62104 | Cri | 0.65 | 10.0 | 0.01 | Sep 17, 2026 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | ||
| CVE-2026-73456 | Cri | 0.65 | 10.0 | 0.01 | Sep 16, 2026 | Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control… | ||
| CVE-2026-73453 | Cri | 0.65 | 10.0 | 0.01 | Sep 16, 2026 | An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By… | ||
| CVE-2026-14560 | Cri | 0.65 | 10.0 | 0.00 | Sep 11, 2026 | The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the… | ||
| CVE-2026-6876 | Cri | 0.65 | — | 0.00 | Aug 27, 2026 | ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow… | ||
| CVE-2026-18885 | Cri | 0.65 | — | 0.00 | Aug 27, 2026 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify,… | ||
| CVE-2026-76605 | Cri | 0.65 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2. | ||
| CVE-2026-76604 | Cri | 0.65 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes. | ||
| CVE-2026-67364 | Cri | 0.65 | — | 0.00 | Aug 19, 2026 | Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X]… | ||
| CVE-2026-73343 | Cri | 0.65 | 10.0 | 0.01 | Aug 18, 2026 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | ||
| CVE-2026-74253 | Cri | 0.65 | — | 0.00 | Aug 17, 2026 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated. | ||
| CVE-2026-73678 | Cri | 0.65 | 10.0 | 0.01 | Aug 14, 2026 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which… | ||
| CVE-2026-61962 | Cri | 0.65 | 10.0 | 0.00 | Aug 13, 2026 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | ||
| CVE-2026-27544 | Cri | 0.65 | 10.0 | 0.01 | Aug 13, 2026 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | ||
| CVE-2026-67282 | Cri | 0.65 | — | 0.01 | Aug 12, 2026 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model. | ||
| CVE-2026-58231 | Cri | 0.65 | 10.0 | 0.02 | Aug 11, 2026 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components,… |
- risk 0.66cvss 8.8epss 0.67
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API…
- risk 0.66cvss 9.8epss 0.81
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated…
- risk 0.66cvss 10.0epss 0.07
HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
- risk 0.66cvss 9.8epss 0.31
The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka "Web Services…
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
- risk 0.65cvss 10.0epss 0.01
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control…
- risk 0.65cvss 10.0epss 0.01
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By…
- risk 0.65cvss 10.0epss 0.00
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the…
- risk 0.65cvss —epss 0.00
ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow…
- risk 0.65cvss —epss 0.00
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify,…
- risk 0.65cvss —epss 0.00
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
- risk 0.65cvss —epss 0.00
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.
- risk 0.65cvss —epss 0.00
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X]…
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- risk 0.65cvss —epss 0.00
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.
- risk 0.65cvss 10.0epss 0.01
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which…
- risk 0.65cvss 10.0epss 0.00
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
- risk 0.65cvss —epss 0.01
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.
- risk 0.65cvss 10.0epss 0.02
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components,…