CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,138 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 125 of 143
- CVE-2026-26030CRITICALCVSS 9.9EG 9.92026-02-19
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `pyth…
- CVE-2026-26045HIGHCVSS 7.2EG 7.22026-02-21
A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-si…
- CVE-2026-26056HIGHCVSS 8.8EG 8.82026-02-12
Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. It allows users with CR create/update permissions to execute arbitr…
- CVE-2026-26216CRITICALCVSS 10.0EG 10.02026-02-12
Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was inc…
- CVE-2026-2622MEDIUMCVSS 5.4EG 5.42026-02-17
A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blossom-backend/backend/src/main/java/com/blossom/backend/server/article/draft/ArticleController.java of the component Articl…
- CVE-2026-26332CRITICALCVSS 10.0EG 10.02026-05-04
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
- CVE-2026-26379MEDIUMCVSS 6.5EG 6.52026-06-03
Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configuration. This allows authenticated attackers to perform internal network scanning and identify running services by analyzi…
- CVE-2026-26682HIGHCVSS 7.8EG 7.82026-02-26
An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java component
- CVE-2026-26699HIGHCVSS 7.2EG 8.82026-03-02
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.
- CVE-2026-26720CRITICALCVSS 9.8EG 9.82026-03-02
An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.
- CVE-2026-26830CRITICALCVSS 9.8EG 9.82026-03-25
pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths i…
- CVE-2026-26831CRITICALCVSS 9.8EG 9.82026-03-25
textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.…
- CVE-2026-26833CRITICALCVSS 9.8EG 9.82026-03-25
thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sani…
- CVE-2026-26954CRITICALCVSS 10.0EG 10.02026-03-13
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fromEntries, it is possible to construct …
- CVE-2026-2701CRITICALCVSS 9.1EG 9.12026-04-02
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
- CVE-2026-27044CRITICALCVSS 9.9EG 9.92026-03-25
Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0.
- CVE-2026-27174CRITICALCVSS 9.8EG 9.82026-02-18
MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes execution to continue past a redirect() call that lacks an…
- CVE-2026-27436CRITICALCVSS 9.1EG 9.12026-07-02
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
- CVE-2026-27464MEDIUMCVSS 6.5EG 6.52026-02-21
Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credent…
- CVE-2026-27493CRITICALCVSS 9.0EG 9.02026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an unauthenticated attacker to inject and eva…
- CVE-2026-27495CRITICALCVSS 9.9EG 9.92026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could exploit a vulnerability in the JavaScript Task Runner sandbox to e…
- CVE-2026-27497HIGHCVSS 8.8EG 8.82026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's SQL query mode to execute arbitrary code…
- CVE-2026-27498HIGHCVSS 8.8EG 8.82026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk node with git operations to achieve rem…
- CVE-2026-27544CRITICALCVSS 10.0EG 10.02026-08-13
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
- CVE-2026-27574CRITICALCVSS 9.9EG 9.92026-02-21
OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied…
- CVE-2026-27577CRITICALCVSS 9.9EG 9.92026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user wit…
- CVE-2026-27597CRITICALCVSS 10.0EG 10.02026-02-25
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE…
- CVE-2026-27674MEDIUMCVSS 6.1EG 6.12026-04-14
Due to a Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java), an unauthenticated attacker could supply crafted input that is interpreted by the application and causes it to reference attacker-controlled …
- CVE-2026-27675LOWCVSS 2.0EG 2.02026-04-14
SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modifi…
- CVE-2026-27701HIGHCVSS 8.8EG 8.82026-02-25
LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveCode's `i18n-update-pull` GitHub Actions workflow is vulnerable to JavaScript injection. The title of the Pull Request a…
- CVE-2026-27702CRITICALCVSS 9.0EG 9.02026-02-25
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability in Budibase's view filtering implementation allows any authenticated user (including free t…
- CVE-2026-27744CRITICALCVSS 9.8EG 9.82026-02-25
The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later …
- CVE-2026-27745HIGHCVSS 8.8EG 8.82026-02-25
The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form fiel…
- CVE-2026-27760HIGHCVSS 8.1EG 8.22026-04-28
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action pa…
- CVE-2026-27830HIGHCVSS 8.0EG 8.02026-02-26
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOv…
- CVE-2026-27876CRITICALCVSS 9.1EG 9.12026-03-27
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future a…
- CVE-2026-27952CRITICALCVSS 9.9EG 9.92026-02-26
Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a sandboxing mechanism for user-supplied eval…
- CVE-2026-27966CRITICALCVSS 9.8EG 9.82026-02-26
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`pytho…
- CVE-2026-27984CRITICALCVSS 9.0EG 9.02026-03-05
Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This issue affects Widget Options: from n/a through <= 4.1.3.
- CVE-2026-28134HIGHCVSS 8.5EG 8.52026-03-05
Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through <= 3.7.2.
- CVE-2026-2825LOWCVSS 3.5EG 3.52026-02-20
A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file tools/fix.py of the component Article Module. The manipulation leads to cross site scripting. It is possible to initiate…
- CVE-2026-2830MEDIUMCVSS 6.1EG 6.12026-03-06
The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insuffici…
- CVE-2026-28425HIGHCVSS 8.0EG 8.02026-02-27
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the appl…
- CVE-2026-28505CRITICALCVSS 10.0EG 10.02026-03-30
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed eval() for notification text templates. The sandbox attempts …
- CVE-2026-28783CRITICALCVSS 9.1EG 9.12026-03-04
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be abl…
- CVE-2026-28797HIGHCVSS 8.8EG 8.82026-04-03
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message com…
- CVE-2026-28801HIGHCVSS 7.8EG 7.82026-03-06
Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code contained inside of a pattern or path file is executed by the macro. Since users commonly share path/pattern files, an atta…
- CVE-2026-2897MEDIUMCVSS 4.8EG 4.82026-02-22
A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads …
- CVE-2026-29014CRITICALCVSS 9.8EG 9.82026-04-01
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficie…
- CVE-2026-29039HIGHCVSS 7.5EG 7.52026-03-06
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io application allows users to specify XPath expressions as content filters via the include_filters field. These XPath ex…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →