CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 44 of 143
- CVE-2018-10429CRITICALCVSS 9.8EG 9.82018-04-26
Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php.
- CVE-2018-10515HIGHCVSS 7.2EG 7.22018-04-27
In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted ZIP archive.
- CVE-2018-10517HIGHCVSS 7.2EG 7.22018-04-27
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a da…
- CVE-2018-10574CRITICALCVSS 9.8EG 9.82018-04-30
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/apis/storage.php does not prevent uploads of .htaccess file…
- CVE-2018-10642HIGHCVSS 7.2EG 7.22018-05-02
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php contains a function ca…
- CVE-2018-10740CRITICALCVSS 9.8EG 9.82018-05-04
Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file.
- CVE-2018-1104HIGHCVSS 8.8EG 8.82018-05-02
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.
- CVE-2018-11228CRITICALCVSS 9.8EG 9.82018-06-08
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP).
- CVE-2018-1133HIGHCVSS 8.8EG 8.82018-05-25
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
- CVE-2018-11587CRITICALCVSS 9.8EG 9.82018-06-25
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.
- CVE-2018-11780CRITICALCVSS 9.8EG 9.82018-09-17
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
- CVE-2018-11781HIGHCVSS 7.8EG 7.82018-09-17
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
- CVE-2018-1207CRITICALCVSS 9.8EG 9.82018-03-23
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentially be able to use CGI variables to execute remote code.
- CVE-2018-12531CRITICALCVSS 9.8EG 9.82018-06-18
An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271.
- CVE-2018-1260CRITICALCVSS 9.8EG 9.82018-05-11
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an author…
- CVE-2018-1270CRITICALCVSS 9.8EG 9.82018-04-06
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging m…
- CVE-2018-1273CRITICALCVSS 9.8EG 9.8⚠ KEV2018-04-11
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (…
- CVE-2018-1275CRITICALCVSS 9.8EG 9.82018-04-11
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging m…
- CVE-2018-12994HIGHCVSS 8.8EG 8.82018-06-29
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen.
- CVE-2018-12995HIGHCVSS 8.8EG 8.82018-06-29
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.
- CVE-2018-13043CRITICALCVSS 9.8EG 9.82018-07-01
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
- CVE-2018-13818CRITICALCVSS 9.8EG 9.82018-07-10
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web applications using Tw…
- CVE-2018-14399CRITICALCVSS 9.8EG 9.82018-07-19
libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SRC attribute of an IMG element within info[content] JSON data to the index.php?m=member&c=i…
- CVE-2018-14421HIGHCVSS 8.8EG 8.82018-07-20
SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploi…
- CVE-2018-14579CRITICALCVSS 9.8EG 9.82018-07-24
GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by inserting this code into the "Database Information" "Table prefix" form field, or obtain …
- CVE-2018-14630HIGHCVSS 8.8EG 8.82018-09-17
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to i…
- CVE-2018-14667CRITICALCVSS 9.8EG 9.8⚠ KEV2018-11-06
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized o…
- CVE-2018-14716HIGHCVSS 7.5EG 7.62018-08-06
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.
- CVE-2018-14804CRITICALCVSS 9.8EG 9.82018-10-01
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.
- CVE-2018-14910HIGHCVSS 8.8EG 8.82018-08-03
SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php or data/admin/ip.php. This can also be ex…
- CVE-2018-15728HIGHCVSS 8.8EG 8.82018-08-24
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Admin' role assigned could send arbitrary Erlang code to the 'diag/eval' endpoint of the API…
- CVE-2018-15886HIGHCVSS 7.2EG 7.22018-09-10
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to execute arbitrary PHP code by placing th…
- CVE-2018-16168CRITICALCVSS 9.8EG 9.82019-01-09
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
- CVE-2018-16343HIGHCVSS 7.2EG 7.22018-09-02
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
- CVE-2018-16604HIGHCVSS 7.2EG 7.22018-09-06
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").
- CVE-2018-16771CRITICALCVSS 9.8EG 9.82018-09-10
Hoosk v1.7.0 allows PHP code execution via a SiteUrl that is provided during installation and mishandled in config.php.
- CVE-2018-16975CRITICALCVSS 9.8EG 9.82018-09-12
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insuf…
- CVE-2018-17030HIGHCVSS 7.5EG 7.52018-09-14
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php.
- CVE-2018-17036CRITICALCVSS 9.8EG 9.82018-09-14
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
- CVE-2018-17126CRITICALCVSS 9.8EG 9.82018-09-17
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
- CVE-2018-17131HIGHCVSS 7.2EG 7.22018-09-17
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
- CVE-2018-17132HIGHCVSS 7.2EG 7.22018-09-17
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
- CVE-2018-17133HIGHCVSS 7.2EG 7.22018-09-17
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
- CVE-2018-17134HIGHCVSS 7.2EG 7.22018-09-17
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.
- CVE-2018-17170HIGHCVSS 8.1EG 8.12019-06-28
Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend versions prior to prod-2018-11-13-15-00-42 are affected.
- CVE-2018-17173CRITICALCVSS 9.8EG 9.82018-09-21
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
- CVE-2018-17207CRITICALCVSS 9.8EG 9.82018-09-19
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving ar…
- CVE-2018-17364HIGHCVSS 8.1EG 8.12018-09-23
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.
- CVE-2018-17827HIGHCVSS 7.2EG 7.22018-10-01
HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into app/admin/model/AdminPlugins.php.
- CVE-2018-1792HIGHCVSS 8.8EG 8.82018-11-13
IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privileges. IBM X-Force ID: 148947.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →