CWE-470— Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection)
The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.— MITRE CWE catalog
123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-470page 3 of 3
- CVE-2026-34216MEDIUMCVSS 6.6EG 6.62026-05-19
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly from user-supplied request input and used it for dynamic static…
- CVE-2026-105064MEDIUMCVSS 6.5EG 6.52026-10-05
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Inj…
- CVE-2026-96740MEDIUMCVSS 6.5EG 6.52026-09-28
A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allo…
- CVE-2026-64663MEDIUMCVSS 6.5EG 6.52026-08-06
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose template…
- CVE-2026-46718MEDIUMCVSS 6.5EG 6.52026-06-02
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes …
- CVE-2025-61925MEDIUMCVSS 6.5EG 6.52025-10-10
Astro is a web framework. Prior to version 5.14.2, Astro reflects the value in `X-Forwarded-Host` in output when using `Astro.url` without any validation. It is common for web servers such as nginx to route requests via the `Host` header, …
- CVE-2023-37207MEDIUMCVSS 6.5EG 6.52023-07-05
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Fi…
- CVE-2026-96672MEDIUMCVSS 6.4EG 6.42026-09-23
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python path…
- CVE-2018-25239MEDIUMCVSS 6.2EG 6.22026-04-04
Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top righ…
- CVE-2026-53666MEDIUMCVSS 6.1EG 6.12026-07-23
React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for a…
- CVE-2024-22258MEDIUMCVSS 6.1EG 6.12024-03-20
Spring Authorization Server versions 1.0.0 - 1.0.5, 1.1.0 - 1.1.5, 1.2.0 - 1.2.2 and older unsupported versions are susceptible to a PKCE Downgrade Attack for Confidential Clients. Specifically, an application is vulnerable when a Confide…
- CVE-2019-20635MEDIUMCVSS 6.1EG 6.12020-04-02
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.
- CVE-2026-63317MEDIUMCVSS 5.6EG 5.62026-07-24
Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code paths in Apache OpenNLP load a class by its fully-quali…
- CVE-2023-35680MEDIUMCVSS 5.5EG 5.52023-09-11
In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not ne…
- CVE-2004-2331MEDIUMCVSS 5.5EG 5.52004-12-31
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject …
- CVE-2026-19135MEDIUMCVSS 5.4EG 5.42026-08-13
A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Jav…
- CVE-2026-19032MEDIUMCVSS 5.3EG 5.32026-09-01
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(va…
- CVE-2026-48817MEDIUMCVSS 5.3EG 5.32026-06-15
Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting…
- CVE-2026-23923MEDIUMCVSS 5.3EG 5.32026-03-24
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
- CVE-2026-102580MEDIUMCVSS 4.3EG 4.32026-09-30
A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class instantiation. This vulnerability enables the unauthorized creation of i…
- CVE-2026-54614MEDIUMCVSS 4.3EG 4.32026-08-26
DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passes …
- CVE-2026-57284MEDIUMCVSS 4.3EG 4.32026-06-24
Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration othe…
- CVE-2022-23744LOWCVSS 2.3EG 2.32022-07-07
Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.
Map vulnerabilities like CWE-470 to your infrastructure
EchelonGraph correlates every CVE — across CWE-470 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →