CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 45 of 143
- CVE-2018-1808HIGHCVSS 4.3EG 8.82018-11-13
IBM WebSphere Commerce 9.0.0.0 through 9.0.0.6 could allow some server-side code injection due to inadequate input control. IBM X-Force ID: 149828.
- CVE-2018-18083CRITICALCVSS 9.8EG 9.82018-10-09
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
- CVE-2018-18249CRITICALCVSS 9.8EG 9.82018-12-17
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to …
- CVE-2018-18258CRITICALCVSS 9.8EG 9.82018-10-11
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.
- CVE-2018-18319CRITICALCVSS 9.8EG 9.82018-10-15
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI.…
- CVE-2018-18426HIGHCVSS 8.8EG 8.82018-10-17
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt parameter.
- CVE-2018-18461CRITICALCVSS 9.8EG 9.82018-10-18
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.
- CVE-2018-18573HIGHCVSS 7.2EG 7.22019-08-22
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code executio…
- CVE-2018-18835CRITICALCVSS 9.8EG 9.82018-10-30
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.
- CVE-2018-18836MEDIUMCVSS 6.5EG 6.52019-06-18
An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client_api_request_v1_data in web/api/web_api_v1.c.
- CVE-2018-18879HIGHCVSS 8.8EG 8.82019-06-18
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
- CVE-2018-18892CRITICALCVSS 9.8EG 9.82018-11-01
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
- CVE-2018-18903CRITICALCVSS 9.8EG 9.82018-11-03
Vanilla 2.6.x before 2.6.4 allows remote code execution.
- CVE-2018-19002HIGHCVSS 7.8EG 7.82019-02-05
LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash.
- CVE-2018-19011HIGHCVSS 8.8EG 8.82019-01-22
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
- CVE-2018-19053HIGHCVSS 7.2EG 7.22018-11-07
PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code.
- CVE-2018-19127CRITICALCVSS 9.8EG 9.82018-11-09
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template paramet…
- CVE-2018-19180CRITICALCVSS 9.8EG 9.82018-11-11
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written…
- CVE-2018-19196CRITICALCVSS 9.8EG 9.82018-11-12
An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard admin\controller\uploadfile.php restrictions on uploaded file types (jpg, jpeg, bmp, png, …
- CVE-2018-19220CRITICALCVSS 9.8EG 9.82018-11-12
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
- CVE-2018-19404HIGHCVSS 7.2EG 7.22018-11-21
In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating a ZIP archive containing a config.php file, hosting the .zip file at an external URL, and…
- CVE-2018-19463HIGHCVSS 8.8EG 8.82018-11-22
zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content type in an upload to the zb_system/admin/index.php?act=UploadMng URI. NOTE: The vendor's pos…
- CVE-2018-19520HIGHCVSS 8.8EG 8.82018-11-25
An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain PHP functions such as eval, but does not prevent use of preg_replace 'e' calls, allowing u…
- CVE-2018-19595CRITICALCVSS 9.8EG 9.82018-11-27
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an in…
- CVE-2018-19641CRITICALCVSS 6.1EG 9.82019-03-27
Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
- CVE-2018-1999019CRITICALCVSS 9.8EG 9.82018-07-23
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be explo…
- CVE-2018-1999022CRITICALCVSS 9.8EG 9.82018-07-23
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _fin…
- CVE-2018-1999023HIGHCVSS 8.8EG 8.82018-07-23
The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading special…
- CVE-2018-20027CRITICALCVSS 9.8EG 9.82018-12-17
The yaml_parse.load method in Pylearn2 allows code injection.
- CVE-2018-20129HIGHCVSS 8.8EG 8.82018-12-13
An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the ima…
- CVE-2018-20133CRITICALCVSS 9.8EG 9.82018-12-17
ymlref allows code injection.
- CVE-2018-20300CRITICALCVSS 9.8EG 9.82018-12-20
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
- CVE-2018-20325CRITICALCVSS 9.8EG 9.82018-12-21
There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.
- CVE-2018-20599HIGHCVSS 8.8EG 8.82018-12-30
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
- CVE-2018-20605CRITICALCVSS 9.8EG 9.82018-12-30
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.
- CVE-2018-20717HIGHCVSS 8.8EG 8.82019-01-15
In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of at least a Salesman or higher privileges. The attacker can then inject arbitrary PHP objec…
- CVE-2018-20768CRITICALCVSS 9.8EG 9.82019-02-10
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leverag…
- CVE-2018-20772HIGHCVSS 7.2EG 7.22019-02-11
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.
- CVE-2018-20773HIGHCVSS 7.2EG 7.22019-02-11
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.
- CVE-2018-20775HIGHCVSS 7.2EG 7.22019-02-11
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
- CVE-2018-20896LOWCVSS 3.9EG 3.92019-08-01
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
- CVE-2018-20931MEDIUMCVSS 6.3EG 6.32019-08-01
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
- CVE-2018-20988HIGHCVSS 7.5EG 7.52019-08-22
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
- CVE-2018-21005CRITICALCVSS 9.8EG 9.82019-08-27
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
- CVE-2018-21023HIGHCVSS 8.8EG 8.82019-10-08
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
- CVE-2018-2363HIGHCVSS 8.8EG 8.82018-01-09
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour …
- CVE-2018-2418CRITICALCVSS 5.5EG 9.82018-05-09
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- CVE-2018-2427HIGHCVSS 8.8EG 8.82018-07-10
SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could th…
- CVE-2018-2491HIGHCVSS 7.8EG 7.82018-11-13
When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL contains malicious JavaScript code it can eventually run inside the built-in log viewer of the…
- CVE-2018-25114CRITICALCVSS 9.3EG 9.32025-07-23
A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessib…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →