CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,137 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 107 of 143
- CVE-2025-47916CRITICALCVSS 10.0EG 10.02025-05-16
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a p…
- CVE-2025-47988HIGHCVSS 7.5EG 7.52025-07-08
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2025-48100CRITICALCVSS 9.1EG 9.12025-08-28
Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbuystoreintegrator allows Remote Code Inclusion.This issue affects bidorbuy Store Integrator: from n/a through <= 2.12.0.
- CVE-2025-48119MEDIUMCVSS 5.3EG 5.32025-05-16
Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP Book Showcase rs-wp-books-showcase allows Code Injection.This issue affects RS WP Book Showcase: from n/a through <= 6.7.59.
- CVE-2025-48120MEDIUMCVSS 5.3EG 5.32025-05-16
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps allows Code Injection.This issue affects MapSVG: from n/a through <= 8.6.9.
- CVE-2025-48123CRITICALCVSS 10.0EG 10.02025-06-09
Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Code…
- CVE-2025-48140CRITICALCVSS 9.9EG 9.92025-06-09
Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI metalpriceapi allows Code Injection.This issue affects MetalpriceAPI: from n/a through <= 1.1.4.
- CVE-2025-48169CRITICALCVSS 9.9EG 9.92025-08-20
Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Remote Code Inclusion.This issue affects Code Engine: from n/a through <= 0.3.3.
- CVE-2025-48390HIGHCVSS 7.2EG 7.22025-05-29
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code injection due to insufficient validation of user input in the php_path parameter. The backticks characters are not remo…
- CVE-2025-4852LOWCVSS 2.4EG 2.42025-05-18
A vulnerability, which was classified as problematic, has been found in TOTOLINK A3002R 2.1.1-B20230720.1011. This issue affects some unknown processing of the component VPN Page. The manipulation of the argument Comment leads to cross sit…
- CVE-2025-4858LOWCVSS 2.4EG 2.42025-05-18
A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been declared as problematic. This vulnerability affects unknown code of the file /adv_arpspoofing.php of the component ARP Spoofing Prevention Page. The manip…
- CVE-2025-4859LOWCVSS 2.4EG 2.42025-05-18
A vulnerability was found in D-Link DAP-2695 120b36r137_ALL_en_20210528. It has been rated as problematic. This issue affects some unknown processing of the file /adv_macbypass.php of the component MAC Bypass Settings Page. The manipulatio…
- CVE-2025-4860LOWCVSS 2.4EG 2.42025-05-18
A vulnerability classified as problematic has been found in D-Link DAP-2695 120b36r137_ALL_en_20210528. Affected is an unknown function of the file /adv_dhcps.php of the component Static Pool Settings Page. The manipulation of the argument…
- CVE-2025-4862MEDIUMCVSS 4.3EG 4.32025-05-18
A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /searchdata.php. The manipulation of the argument searchda…
- CVE-2025-4866MEDIUMCVSS 6.3EG 6.32025-05-18
A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical. Affected is an unknown function of the component Management Console. The manipulation leads to code injection. It is possible to launch the attack …
- CVE-2025-48984HIGHCVSS 8.8EG 8.82025-10-31
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
- CVE-2025-49013CRITICALCVSS 9.9EG 9.92025-06-09
WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user cont…
- CVE-2025-49029CRITICALCVSS 9.1EG 9.12025-07-01
Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.kazi Custom Login And Signup Widget custom-login-and-signup-widget allows Code Injection.This issue affects Custom Login And Signup Widget: from n/a through <…
- CVE-2025-49132CRITICALCVSS 10.0EG 10.02025-06-20
Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being aut…
- CVE-2025-49250MEDIUMCVSS 4.3EG 4.32025-06-06
Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase team-showcase-cm allows Code Injection.This issue affects Team Showcase: from n/a through < 25.05.13.
- CVE-2025-49302CRITICALCVSS 10.0EG 10.02025-07-04
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows Remote Code Inclusion.This issue affects Easy Stripe: from n/a through <= 1.1.
- CVE-2025-49372CRITICALCVSS 10.0EG 10.02025-11-06
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7.
- CVE-2025-4939MEDIUMCVSS 4.3EG 4.32025-05-19
A vulnerability classified as problematic was found in PHPGurukul Credit Card Application Management System 1.0. This vulnerability affects unknown code of the file /admin/new-ccapplication.php. The manipulation leads to cross site scripti…
- CVE-2025-49521HIGHCVSS 8.8EG 8.82025-06-30
A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute …
- CVE-2025-49581HIGHCVSS 8.8EG 8.82025-06-13
XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki inst…
- CVE-2025-49704CRITICALCVSS 8.8EG 9.0⚠ KEV2025-07-08
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-49887CRITICALCVSS 9.9EG 9.92025-08-14
Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Remote Code Inclusion.This issue affects Product XML Feed Manager for Wo…
- CVE-2025-49926HIGHCVSS 7.2EG 7.32025-10-22
Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium kalium allows Code Injection.This issue affects Kalium: from n/a through <= 3.25.
- CVE-2025-4996LOWCVSS 2.4EG 2.42025-05-20
A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5. This issue affects some unknown processing of the component Add Static IP. The manipulation of the argument Description leads to cross site sc…
- CVE-2025-5007LOWCVSS 3.5EG 3.52025-05-20
A vulnerability was found in Part-DB up to 1.17.0. It has been declared as problematic. Affected by this vulnerability is the function handleUpload of the file src/Services/Attachments/AttachmentSubmitHandler.php of the component Profile P…
- CVE-2025-5010MEDIUMCVSS 4.7EG 4.72025-05-21
A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog Backend. The manipulation of the argument Description leads to cr…
- CVE-2025-5011MEDIUMCVSS 4.7EG 4.72025-05-21
A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List Page. The manipulation leads to cross site scriptin…
- CVE-2025-50123HIGHCVSS 7.2EG 7.22025-07-11
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote command execution by a privileged account when the server is accessed via a console and through exploitation of the hostname …
- CVE-2025-5013MEDIUMCVSS 4.7EG 4.72025-05-21
A vulnerability, which was classified as problematic, was found in HkCms up to 2.3.2.240702. This affects an unknown part of the file /index.php/search/index.html of the component Search. The manipulation of the argument keyword leads to c…
- CVE-2025-50567CRITICALCVSS 10.0EG 10.02025-08-19
Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e (eval) modifier to interpolate SQL query parameters. This leads to injection of user-control…
- CVE-2025-50692CRITICALCVSS 9.8EG 9.82025-08-07
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
- CVE-2025-50706CRITICALCVSS 9.8EG 9.82025-08-05
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function
- CVE-2025-50707CRITICALCVSS 9.8EG 9.82025-08-05
An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component
- CVE-2025-50739CRITICALCVSS 9.8EG 9.82025-10-30
iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization.
- CVE-2025-50881HIGHCVSS 8.8EG 8.82026-03-16
The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, the script takes user-supplied input from the `action` URL parameter, performs ins…
- CVE-2025-5101MEDIUMCVSS 5.0EG 5.02025-08-27
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appe…
- CVE-2025-5120CRITICALCVSS 10.0EG 10.02025-07-27
A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code execution (RCE). The vulnerability stems from the local_pytho…
- CVE-2025-5127MEDIUMCVSS 5.4EG 5.42025-05-24
A vulnerability was determined in Teledyne FLIR AX8 up to 1.46.16. This issue affects some unknown processing of the file /prod.php. Executing manipulation of the argument cmd can lead to cross site scripting. The attack may be launched re…
- CVE-2025-5133MEDIUMCVSS 6.1EG 6.12025-05-24
A vulnerability classified as problematic has been found in Tmall Demo up to 20250505. Affected is an unknown function of the component Search Box. The manipulation leads to cross site scripting. It is possible to launch the attack remotel…
- CVE-2025-5134MEDIUMCVSS 6.1EG 6.12025-05-24
A vulnerability classified as problematic was found in Tmall Demo up to 20250505. Affected by this vulnerability is an unknown functionality of the component Buy Item Page. The manipulation of the argument Detailed Address leads to cross s…
- CVE-2025-5135MEDIUMCVSS 6.1EG 6.12025-05-24
A vulnerability, which was classified as problematic, has been found in Tmall Demo up to 20250505. Affected by this issue is some unknown functionality of the file /tmall/admin/ of the component Product Details Page. The manipulation of th…
- CVE-2025-5137HIGHCVSS 7.2EG 7.22025-05-25
A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an unknown function of the file dede/sys_verifies.php?action=getfiles of the component Incomplete Fix CVE-2018-9175. The manipulation of the argu…
- CVE-2025-5138LOWCVSS 3.5EG 3.52025-05-25
A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component PDF File Handler. The manipulation leads to cross site scripting. The att…
- CVE-2025-51387CRITICALCVSS 9.8EG 9.82025-08-04
The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabl…
- CVE-2025-51414HIGHCVSS 8.8EG 8.82026-04-13
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →