CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,145 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 141 of 143
- CVE-2026-7501LOWCVSS 3.5EG 3.52026-04-30
A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site sc…
- CVE-2026-75077MEDIUMCVSS 4.3EG 4.32026-08-17
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument course leads to cross site scripting. Th…
- CVE-2026-75078MEDIUMCVSS 4.3EG 4.32026-08-17
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site scripting. Remote exp…
- CVE-2026-7508MEDIUMCVSS 6.3EG 6.32026-04-30
A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code…
- CVE-2026-75149HIGHCVSS 8.8EG 8.82026-08-19
marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embed…
- CVE-2026-75357CRITICALCVSS 9.8EG 9.82026-08-27
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
- CVE-2026-75411CRITICALCVSS 9.8EG 9.82026-08-26
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dyna…
- CVE-2026-75414CRITICALCVSS 9.8EG 9.82026-08-26
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.
- CVE-2026-7580MEDIUMCVSS 5.3EG 5.32026-05-01
A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attac…
- CVE-2026-75827HIGHCVSS 8.8EG 8.82026-08-18
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access …
- CVE-2026-75858HIGHCVSS 7.8EG 7.82026-08-18
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats…
- CVE-2026-75911HIGHCVSS 7.8EG 7.82026-08-18
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml f…
- CVE-2026-7595MEDIUMCVSS 6.3EG 6.32026-05-01
A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config…
- CVE-2026-7596MEDIUMCVSS 4.3EG 4.32026-05-01
A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such m…
- CVE-2026-76148HIGHCVSS 7.8EG 7.82026-08-26
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
- CVE-2026-76224HIGHCVSS 8.8EG 8.82026-08-19
ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure java (gremlin-lang) engine, ArcadeGremlin.execu…
- CVE-2026-76314HIGHCVSS 8.8EG 8.82026-08-19
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. …
- CVE-2026-76315HIGHCVSS 8.8EG 8.82026-08-19
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute arbitrary code on the Splunk platform instance through Splunk Web Manager Configuration. The…
- CVE-2026-76335HIGHCVSS 8.8EG 8.82026-08-19
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write a malicious Splunk Web Manager Extensible Markup Language (XML) configu…
- CVE-2026-76604CRITICALCVSS 10.0EG 10.02026-08-22
Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.
- CVE-2026-76605CRITICALCVSS 10.0EG 10.02026-08-22
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
- CVE-2026-76635HIGHCVSS 7.2EG 7.22026-08-20
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence …
- CVE-2026-7669MEDIUMCVSS 5.6EG 5.62026-05-02
A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the a…
- CVE-2026-76760HIGHCVSS 7.3EG 7.32026-08-19
A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of the argument exec results in code injection. The attack may be perfor…
- CVE-2026-7677LOWCVSS 3.5EG 3.52026-05-03
A vulnerability was determined in kerwincui FastBee up to 1.2.1. The impacted element is the function Add of the file springboot/fastbee-admin/src/main/java/com/fastbee/web/controller/system/SysNoticeController.java of the component System…
- CVE-2026-76836HIGHCVSS 8.8EG 8.82026-08-24
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /ap…
- CVE-2026-76841HIGHCVSS 8.8EG 8.82026-08-24
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional defa…
- CVE-2026-7700MEDIUMCVSS 6.3EG 6.32026-05-03
A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p of the component LambdaFilterComponent. Executing a manipulation can l…
- CVE-2026-7703HIGHCVSS 7.3EG 7.32026-05-03
A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. Impacted is an unknown function of the component Websocket API. This manipulation causes code injection. The attack can be initiated remotely. The exploit has been …
- CVE-2026-77074MEDIUMCVSS 6.5EG 6.52026-08-20
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticated users to inject MVG primitives. Attackers can craft malicious text values to issue blin…
- CVE-2026-77075HIGHCVSS 7.3EG 7.32026-08-20
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview rendering. The editor spliced the field's stored value directly into the node type's URL …
- CVE-2026-77077HIGHCVSS 7.6EG 7.62026-08-20
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal module constructors such as EventEmitter, allowing an…
- CVE-2026-77413CRITICALCVSS 9.3EG 9.32026-08-21
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An a…
- CVE-2026-77414CRITICALCVSS 9.3EG 9.32026-08-21
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototyp…
- CVE-2026-77415CRITICALCVSS 9.3EG 9.32026-08-21
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects throug…
- CVE-2026-77647CRITICALCVSS 9.8EG 9.82026-08-20
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such …
- CVE-2026-77806CRITICALCVSS 9.8EG 9.82026-08-21
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resulta…
- CVE-2026-77939MEDIUMCVSS 6.5EG 6.52026-08-28
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony Expression…
- CVE-2026-77956HIGHCVSS 8.9EG 8.92026-08-31
Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2.…
- CVE-2026-77992CRITICALCVSS 9.5EG 9.52026-08-22
Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.
- CVE-2026-78054MEDIUMCVSS 4.3EG 4.32026-08-23
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lead to cross site scripting. The attack ma…
- CVE-2026-78055MEDIUMCVSS 4.3EG 4.32026-08-23
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation of the argument course leads to cross s…
- CVE-2026-78059MEDIUMCVSS 4.3EG 4.32026-08-23
A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site sc…
- CVE-2026-78060MEDIUMCVSS 4.3EG 4.32026-08-23
A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in c…
- CVE-2026-78166MEDIUMCVSS 6.3EG 6.32026-08-24
A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilterTest of the file kafka-ui-api/src/main/java/com/provectus/kafka/ui/controller/MessagesController.java of the comp…
- CVE-2026-78178HIGHCVSS 7.3EG 7.32026-08-24
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype at…
- CVE-2026-78179MEDIUMCVSS 6.3EG 6.32026-08-24
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manip…
- CVE-2026-78180HIGHCVSS 7.3EG 7.32026-08-24
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the a…
- CVE-2026-78181HIGHCVSS 7.3EG 7.32026-08-24
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.…
- CVE-2026-78187LOWCVSS 3.1EG 3.12026-08-24
A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →