VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 95 of 350
  • CVE-2026-8855HigMay 26, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).

  • CVE-2026-44291HigMay 13, 2026
    risk 0.53cvss 8.1epss 0.01

    protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been…

  • CVE-2026-8430HigMay 12, 2026
    risk 0.53cvss 8.1epss 0.00

    SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through…

  • CVE-2026-36340HigApr 30, 2026
    risk 0.53cvss 8.1epss 0.01

    An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

  • CVE-2026-26026CriApr 6, 2026
    risk 0.53cvss 9.1epss 0.11

    GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

  • CVE-2026-2273HigMar 10, 2026
    risk 0.53cvss 8.2epss 0.00

    CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity…

  • CVE-2025-66294HigDec 1, 2025
    risk 0.53cvss 8.8epss 0.03

    Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, under certain conditions, may also be…

  • CVE-2024-39148HigDec 1, 2025
    risk 0.53cvss 8.1epss 0.01

    The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the service is protected via local firewall.

  • CVE-2025-12762CriNov 13, 2025
    risk 0.53cvss 9.1epss 0.12

    pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting…

  • CVE-2025-61588CriOct 2, 2025
    risk 0.53cvss epss 0.00

    RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary…

  • CVE-2025-8417HigSep 11, 2025
    risk 0.53cvss 8.1epss 0.01

    The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use…

  • CVE-2025-54731HigAug 28, 2025
    risk 0.53cvss 8.1epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showcase allows Object Injection.This issue affects YouTube Showcase: from n/a through <= 3.5.1.

  • CVE-2025-8030HigJul 22, 2025
    risk 0.53cvss 8.1epss 0.00

    Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.

  • CVE-2025-36014HigJul 7, 2025
    risk 0.53cvss 8.2epss 0.00

    IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.

  • CVE-2025-34086HigJul 3, 2025
    risk 0.53cvss 8.8epss 0.02

    Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with valid credentials can inject arbitrary PHP code into the displayname field of the user profile, which is rendered…

  • CVE-2025-1532HigApr 17, 2025
    risk 0.53cvss 8.1epss 0.00

    Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity.

  • CVE-2025-25246HigFeb 5, 2025
    risk 0.53cvss 8.1epss 0.01

    NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.

  • CVE-2024-9132HigJan 10, 2025
    risk 0.53cvss 8.1epss 0.01

    The administrator is able to configure an insecure captive portal script

  • CVE-2024-21571HigDec 6, 2024
    risk 0.53cvss 8.1epss 0.00

    Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbitrary code within the Code Agent container. Exploiting this vulnerability would require an attacker to have network access to the…

  • CVE-2024-46966HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity component.