VYPR

CWE-96

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

BaseDraft

Description

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before inserting the input into an executable resource, such as a library, configuration file, or template.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-35 · CAPEC-73 · CAPEC-77 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (25)

page 1 of 2
  • CVE-2015-2079CriApr 28, 2025
    risk 0.64cvss 9.9epss 0.01

    Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.

  • CVE-2024-13264CriJan 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.

  • CVE-2023-39726CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

  • CVE-2020-6144CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.06

    A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An attacker can send an HTTP request to…

  • CVE-2020-6143CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.06

    A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An attacker can send an HTTP request to…

  • CVE-2025-30091CriMar 25, 2025
    risk 0.61cvss epss 0.01

    In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and…

  • CVE-2022-43938HigApr 3, 2023
    risk 0.59cvss 8.8epss 0.26

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of Pentaho Reports (*.prpt) through the JVM script manager. 

  • CVE-2025-57707HigFeb 11, 2026
    risk 0.57cvss 8.8epss 0.01

    An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to access restricted data / files. We have…

  • CVE-2024-55877CriDec 12, 2024
    risk 0.57cvss 9.9epss 0.02

    XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the…

  • CVE-2024-55662CriDec 12, 2024
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This…

  • CVE-2022-0895CriMar 10, 2022
    risk 0.57cvss 9.8epss 0.02

    Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2024-43400CriAug 19, 2024
    risk 0.52cvss 9.0epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social engineer to trick a user to…

  • CVE-2022-24840CriJun 9, 2022
    risk 0.52cvss 9.1epss 0.02

    django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set, traversal was limited to that location…

  • CVE-2024-13267HigJan 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.

  • CVE-2024-13265HigJan 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.

  • CVE-2025-36595HigJun 27, 2025
    risk 0.47cvss 7.2epss 0.01

    Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code…

  • CVE-2021-39115HigSep 1, 2021
    risk 0.47cvss 7.2epss 0.04

    Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template…

  • CVE-2024-13268MedJan 9, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno allows PHP Local File Inclusion.This issue affects Opigno: from 7.X-1.0 before 7.X-1.23.

  • CVE-2024-0788MedJan 29, 2024
    risk 0.43cvss 6.6epss 0.00

    SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys driver.

  • CVE-2025-7825MedOct 3, 2025
    risk 0.41cvss 6.3epss 0.00

    The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all versions up to, and including, 4.3.2 via deserialization of untrusted input via the wpt_schema_breadcrumbs shortcode. This makes it possible for authenticated…