VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 98 of 350
  • CVE-2019-11594HigApr 29, 2019
    risk 0.53cvss 8.1epss 0.02

    In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect.

  • CVE-2019-11593HigApr 29, 2019
    risk 0.53cvss 8.1epss 0.02

    In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-side session when a web service loads a script for execution using XMLHttpRequest or Fetch, and the script origin has an open redirect.

  • CVE-2013-7468HigMar 7, 2019
    risk 0.53cvss 8.1epss 0.02

    Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.

  • CVE-2018-17364HigSep 23, 2018
    risk 0.53cvss 8.1epss 0.01

    OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.

  • CVE-2018-8074HigMar 21, 2018
    risk 0.53cvss 8.1epss 0.02

    Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.

  • CVE-2018-6488HigFeb 22, 2018
    risk 0.53cvss 8.1epss 0.02

    Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution.

  • CVE-2018-7271HigFeb 21, 2018
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering is not rigorous: one can insert malicious code in the installation process to execute arbitrary commands or obtain a web shell.

  • CVE-2017-16905HigJan 5, 2018
    risk 0.53cvss 8.1epss 0.03

    The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and consequently achieve remote code execution, via a man-in-the-middle attack.

  • CVE-2017-16871HigNov 17, 2017
    risk 0.53cvss 8.1epss 0.02

    The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that…

  • CVE-2016-7967HigDec 23, 2016
    risk 0.53cvss 8.1epss 0.02

    KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

  • CVE-2016-6633HigDec 11, 2016
    risk 0.53cvss 8.1epss 0.04

    An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain PHP installations that are running with the dbase extension. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior…

  • CVE-2016-3171HigApr 12, 2016
    risk 0.53cvss 8.1epss 0.03

    Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

  • CVE-2013-3129HigJul 10, 2013
    risk 0.53cvss 7.8epss 0.32

    Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,…

  • CVE-2012-0014HigFeb 14, 2012
    risk 0.53cvss 7.8epss 0.28

    Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a…

  • CVE-2026-55107criAug 18, 2026
    risk 0.52cvss epss

    ### Summary A guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. ### Details A host embeds bound "Service" objects that guest scripts call across the wasm boundary through the transport dispatcher.…

  • CVE-2026-18245CriJul 30, 2026
    risk 0.52cvss 9.0epss 0.01

    Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio…

  • CVE-2026-62379criJul 24, 2026
    risk 0.52cvss epss

    ## Summary A pre-authentication remote code execution vulnerability affects OpenAM. The remote authentication endpoint (`/authservice`, PLL) accepts an XML element that names an arbitrary Java class, which the server then loads and instantiates without validation. On a default…

  • CVE-2026-21575HigJul 21, 2026
    risk 0.52cvss 8.0epss 0.00

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary…

  • CVE-2026-55570CriJun 24, 2026
    risk 0.52cvss 9.0epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialized into the data-obj HTML attribute of each marketplace card. Because the attribute is single-quoted…

  • CVE-2026-47252criJun 8, 2026
    risk 0.52cvss epss 0.00

    # AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin | Field | Value | | ---------------- | ----- | | Repository | julien040/anyquery | | Affected version | 0.4.4 (commit 0abd460) | | Vulnerability | CWE-94 — Improper Control of…