CWE-95— Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").— MITRE CWE catalog
210 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-95page 1 of 5
- CVE-2026-33017CRITICALCVSS 9.8EG 9.8⚠ KEV2026-03-20
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the op…
- CVE-2025-24893CRITICALCVSS 9.8EG 9.8⚠ KEV2025-02-20
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity a…
- CVE-2024-36401CRITICALCVSS 9.8EG 9.8⚠ KEV2024-07-01
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users throug…
- CVE-2023-7101CRITICALCVSS 7.8EG 9.0⚠ KEV2023-12-24
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type ��…
- CVE-2026-61539CRITICALCVSS 10.0EG 10.02026-08-21
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py…
- CVE-2026-44643CRITICALCVSS 10.0EG 10.02026-05-11
Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. …
- CVE-2026-28505CRITICALCVSS 10.0EG 10.02026-03-30
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed eval() for notification text templates. The sandbox attempts …
- CVE-2025-68271CRITICALCVSS 10.0EG 10.02026-01-13
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-…
- CVE-2025-55728CRITICALCVSS 10.0EG 10.02025-09-09
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote cod…
- CVE-2025-55727CRITICALCVSS 10.0EG 10.02025-09-09
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code…
- CVE-2013-10070CRITICALCVSS 10.0EG 10.02025-08-05
PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A remote attacker can exploit this flaw by crafting a request that i…
- CVE-2024-31996CRITICALCVSS 10.0EG 10.02024-04-10
XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, al…
- CVE-2024-31982CRITICALCVSS 10.0EG 10.02024-04-10
XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code exe…
- CVE-2023-26477CRITICALCVSS 10.0EG 10.02023-03-02
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter),…
- CVE-2022-36010CRITICALCVSS 10.0EG 10.02022-08-15
This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/09a0ca97835b0834ad054563e2fddc6f22bc5d8c/src/components/JsonFunc…
- CVE-2025-54322CRITICALCVSS 9.8EG 10.02025-12-27
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
- CVE-2021-23277CRITICALCVSS 8.3EG 10.02021-04-13
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in loadUserFile function…
- CVE-2026-108263CRITICALCVSS 9.9EG 9.92026-10-09
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/…
- CVE-2026-57149CRITICALCVSS 9.9EG 9.92026-09-22
plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portl…
- CVE-2025-53837CRITICALCVSS 9.9EG 9.92026-09-18
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or …
- CVE-2026-48273CRITICALCVSS 9.9EG 9.92026-09-08
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker c…
- CVE-2026-85165CRITICALCVSS 9.9EG 9.92026-09-03
n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit…
- CVE-2026-19295CRITICALCVSS 9.9EG 9.92026-08-28
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that refe…
- CVE-2026-77810CRITICALCVSS 9.9EG 9.92026-08-21
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query…
- CVE-2026-19626CRITICALCVSS 9.9EG 9.92026-08-14
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsa…
- CVE-2026-73602CRITICALCVSS 9.9EG 9.92026-08-13
Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object wi…
- CVE-2026-61667CRITICALCVSS 9.9EG 9.92026-07-13
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datase…
- CVE-2026-45579CRITICALCVSS 9.9EG 9.92026-07-13
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authentic…
- CVE-2026-1470CRITICALCVSS 9.9EG 9.92026-01-27
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not …
- CVE-2026-23885CRITICALCVSS 9.9EG 9.92026-01-19
Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3, the application uses the Ruby `eval()` function to dynamically execute a string provided by the `resource_handler.engi…
- CVE-2026-0863CRITICALCVSS 9.9EG 9.92026-01-18
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system. The vulnerability can be exploited via t…
- CVE-2025-49013CRITICALCVSS 9.9EG 9.92025-06-09
WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user cont…
- CVE-2024-37901CRITICALCVSS 9.9EG 9.92024-07-31
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` an…
- CVE-2024-31984CRITICALCVSS 9.9EG 9.92024-04-10
XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a specially crafted title, it is possible to trigger remote code execution in the (S…
- CVE-2024-31465CRITICALCVSS 9.9EG 9.92024-04-10
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type `XWiki.Searc…
- CVE-2023-37909CRITICALCVSS 9.9EG 9.92023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arb…
- CVE-2023-40177CRITICALCVSS 9.9EG 9.92023-08-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus ef…
- CVE-2023-37462CRITICALCVSS 9.9EG 9.92023-07-14
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to program…
- CVE-2023-35152CRITICALCVSS 9.9EG 9.92023-06-23
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their first name field and see it executed with programming rights. L…
- CVE-2023-35150CRITICALCVSS 9.9EG 9.92023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute cod…
- CVE-2023-30537CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full acce…
- CVE-2023-29511CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading…
- CVE-2023-29509CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the…
- CVE-2023-29214CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cau…
- CVE-2023-29212CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cau…
- CVE-2023-29211CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki i…
- CVE-2023-29210CRITICALCVSS 9.9EG 9.92023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Veloci…
- CVE-2023-29209CRITICALCVSS 9.9EG 9.92023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Vel…
- CVE-2022-41931CRITICALCVSS 9.9EG 9.92022-11-23
xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrar…
- CVE-2022-41928CRITICALCVSS 9.9EG 9.92022-11-23
XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` mac…
Map vulnerabilities like CWE-95 to your infrastructure
EchelonGraph correlates every CVE — across CWE-95 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →