CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,145 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 138 of 143
- CVE-2026-64633CRITICALCVSS 10.0EG 10.02026-08-04
A vulnerability allowing remote unauthenticated code execution on the agent host.
- CVE-2026-64802HIGHCVSS 7.8EG 7.82026-07-23
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
- CVE-2026-64803HIGHCVSS 7.8EG 7.82026-07-23
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
- CVE-2026-64815CRITICALCVSS 9.8EG 9.82026-07-23
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
- CVE-2026-64850HIGHCVSS 8.7EG 8.72026-08-19
Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dange…
- CVE-2026-6486LOWCVSS 3.5EG 3.52026-04-17
A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname resu…
- CVE-2026-6493LOWCVSS 3.5EG 3.52026-04-17
A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[locale]/(auth)/reset-password/components/reset-password-form.tsx of the component Reset Password Handler. Executing a man…
- CVE-2026-65008CRITICALCVSS 9.8EG 9.82026-07-21
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_a…
- CVE-2026-65082HIGHCVSS 7.8EG 7.82026-08-25
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure…
- CVE-2026-6543HIGHCVSS 8.8EG 8.82026-04-30
IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifyi…
- CVE-2026-65548CRITICALCVSS 9.9EG 9.92026-08-06
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
- CVE-2026-65553CRITICALCVSS 10.0EG 10.02026-08-06
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
- CVE-2026-6559MEDIUMCVSS 4.3EG 4.32026-04-19
A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is …
- CVE-2026-65660HIGHCVSS 8.8EG 8.82026-08-11
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65693HIGHCVSS 7.2EG 7.22026-07-24
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can explo…
- CVE-2026-65804MEDIUMCVSS 6.1EG 6.12026-08-03
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-65880CRITICALCVSS 10.0EG 10.02026-07-28
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.
- CVE-2026-65906CRITICALCVSS 10.0EG 10.02026-07-23
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
- CVE-2026-65907CRITICALCVSS 9.1EG 9.12026-07-23
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
- CVE-2026-6592LOWCVSS 3.5EG 3.52026-04-20
A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of the file app/user_manager.py of the component userdata Endpoint. Such manipulation leads to cross site scripting. The att…
- CVE-2026-6593LOWCVSS 3.5EG 3.52026-04-20
A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file server.py of the component View Endpoint. Performing a manipulation results in cross site scripting. The attack is possible…
- CVE-2026-6594HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was determined in brikcss merge up to 1.3.0. This affects an unknown part. Executing a manipulation of the argument __proto__/constructor.prototype/prototype can lead to improperly controlled modification of object prototyp…
- CVE-2026-65941HIGHCVSS 8.8EG 8.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
- CVE-2026-6600LOWCVSS 3.5EG 3.52026-04-20
A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of the component Frontend React Component R…
- CVE-2026-6603HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command of the file src/AgentScope/tool/_coding/_python.py. This manipulation causes cod…
- CVE-2026-66065HIGHCVSS 8.4EG 8.42026-08-03
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RC…
- CVE-2026-66145CRITICALCVSS 9.1EG 9.12026-08-11
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
- CVE-2026-66147CRITICALCVSS 9.4EG 9.42026-08-11
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
- CVE-2026-66148MEDIUMCVSS 6.3EG 6.32026-08-11
An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.
- CVE-2026-66149HIGHCVSS 7.8EG 7.82026-08-11
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands …
- CVE-2026-66150HIGHCVSS 7.8EG 7.82026-08-11
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands …
- CVE-2026-6619LOWCVSS 3.5EG 3.52026-04-20
A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePreview. The manipulation of the argument file…
- CVE-2026-6621HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype …
- CVE-2026-6622LOWCVSS 2.4EG 2.42026-04-20
A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the file /?\_route=customers/edit/ of the component Customer Handler. Such manipulation leads to cross site scripting. The at…
- CVE-2026-6623LOWCVSS 2.4EG 2.42026-04-20
A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of the file /?_route=settings/users-view/ of the component Profile Page Handler. Performing a manipulation results in cross…
- CVE-2026-6624LOWCVSS 2.4EG 2.42026-04-20
A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the file /?\_route=pool/add of the component Pool List Interface. Executing a manipulation can lead to cross site scripting. T…
- CVE-2026-6633LOWCVSS 3.5EG 3.52026-04-20
A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_admin.php of the component Extended Management Module. The manipulation…
- CVE-2026-6648LOWCVSS 3.5EG 3.52026-04-20
A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component Internal Message Module. Performing a manipulation results in cross site scripting. The attack can be initiated remotely…
- CVE-2026-6651LOWCVSS 2.4EG 2.42026-04-20
A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of the component Inventory Edit Item Page. The manipulation of the argument Item Name results in cross site scripting. The…
- CVE-2026-6652MEDIUMCVSS 4.7EG 4.72026-04-20
A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorage Template Handler. This manipulation causes improper neutrali…
- CVE-2026-66709CRITICALCVSS 9.1EG 9.12026-08-06
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
- CVE-2026-66738HIGHCVSS 8.8EG 8.82026-08-10
SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an in…
- CVE-2026-66745HIGHCVSS 7.5EG 7.52026-07-28
Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's brows…
- CVE-2026-66748HIGHCVSS 8.8EG 8.82026-07-28
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the s…
- CVE-2026-66915CRITICALCVSS 10.0EG 10.02026-08-10
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
- CVE-2026-67282CRITICALCVSS 10.0EG 10.02026-08-12
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.
- CVE-2026-67340CRITICALCVSS 7.2EG 9.82026-08-01
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permiss…
- CVE-2026-67364CRITICALCVSS 10.0EG 10.02026-08-19
Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via…
- CVE-2026-6743LOWCVSS 3.5EG 3.52026-04-21
A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to…
- CVE-2026-6745LOWCVSS 3.5EG 3.52026-04-21
A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →