CWE-95— Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").— MITRE CWE catalog
210 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-95page 3 of 5
- CVE-2026-28370CRITICALCVSS 9.1EG 9.12026-02-27
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result…
- CVE-2025-27603CRITICALCVSS 9.1EG 9.12025-03-07
XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migra…
- CVE-2024-8512CRITICALCVSS 9.1EG 9.12024-10-30
The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 via the 'script' parameter of the hookBeforeStartOptimization() function. This is due to the plugin passing user supplie…
- CVE-2026-27493CRITICALCVSS 9.0EG 9.02026-02-25
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an unauthenticated attacker to inject and eva…
- CVE-2026-27702CRITICALCVSS 9.0EG 9.02026-02-25
Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability in Budibase's view filtering implementation allows any authenticated user (including free t…
- CVE-2024-31986CRITICALCVSS 9.0EG 9.02024-04-10
XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a special crafted documented reference and an `XWiki.SchedulerJobClass` XObject, it is po…
- CVE-2023-50721CRITICALCVSS 8.8EG 9.02023-12-15
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowi…
- CVE-2026-100842HIGHCVSS 8.8EG 8.82026-09-27
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any…
- CVE-2026-19780HIGHCVSS 8.8EG 8.82026-09-15
Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific f…
- CVE-2026-82789HIGHCVSS 8.8EG 8.82026-09-14
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
- CVE-2026-65643HIGHCVSS 8.8EG 8.82026-09-01
Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
- CVE-2026-73601HIGHCVSS 8.8EG 8.82026-08-13
Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables a…
- CVE-2026-69253HIGHCVSS 8.8EG 8.82026-08-04
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process vm2�…
- CVE-2026-67195HIGHCVSS 8.8EG 8.82026-08-04
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes…
- CVE-2026-14380HIGHCVSS 8.8EG 8.82026-07-07
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package…
- CVE-2026-45406HIGHCVSS 8.8EG 8.82026-06-26
Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted sh…
- CVE-2026-50733HIGHCVSS 8.8EG 8.82026-06-05
Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and present…
- CVE-2026-46586HIGHCVSS 8.8EG 8.82026-05-19
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are …
- CVE-2026-42603HIGHCVSS 8.8EG 8.82026-05-11
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_target (privileged trigger) but checks out…
- CVE-2026-40316HIGHCVSS 8.8EG 8.82026-04-15
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. …
- CVE-2026-33618HIGHCVSS 8.8EG 8.82026-04-10
Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin access (obtainable via…
- CVE-2025-65530HIGHCVSS 8.8EG 8.82025-12-12
An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file.
- CVE-2025-66474HIGHCVSS 8.8EG 8.82025-12-10
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 ha…
- CVE-2025-61955HIGHCVSS 8.8EG 8.82025-10-15
A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. Note: Software vers…
- CVE-2024-45851HIGHCVSS 8.8EG 8.82024-09-12
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘IN…
- CVE-2024-45850HIGHCVSS 8.8EG 8.82024-09-12
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘IN…
- CVE-2024-45849HIGHCVSS 8.8EG 8.82024-09-12
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘IN…
- CVE-2024-45848HIGHCVSS 8.8EG 8.82024-09-12
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT’ query containing Python code is ru…
- CVE-2024-45847HIGHCVSS 8.8EG 8.82024-09-12
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPDATE’ query containing Python code is…
- CVE-2024-45846HIGHCVSS 8.8EG 8.82024-09-12
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SELECT WHERE’ clause containing Python cod…
- CVE-2024-6891HIGHCVSS 8.8EG 8.82024-08-08
Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.
- CVE-2024-3562HIGHCVSS 8.8EG 8.82024-06-20
The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the e…
- CVE-2023-6735HIGHCVSS 8.8EG 8.82024-01-12
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
- CVE-2023-50723HIGHCVSS 8.8EG 8.82023-12-15
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missi…
- CVE-2023-0089HIGHCVSS 8.8EG 8.82023-03-08
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below.
- CVE-2026-55094HIGHCVSS 8.7EG 8.72026-09-30
Taskcluster is the task execution framework that supports Mozilla's continuous integration and release processes. Prior to version 100.3.0, Taskcluster is vulnerable to unauthenticated RCE on Taskcluster deployments with an anonymous role …
- CVE-2025-58365HIGHCVSS 8.7EG 8.72025-09-08
The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, the blog application in XWiki allowed remote code execution for any user who has edit right on any page. Normally, these …
- CVE-2026-85486HIGHCVSS 8.6EG 8.62026-10-08
Brocade ASCG before 3.5.0 improperly processes user input by evaluating form data prior to validation. When an authenticated user submits a configuration form, the submitted text could immediately be processed. A malicious actor with basic…
- CVE-2026-76190HIGHCVSS 8.6EG 8.62026-09-08
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit t…
- CVE-2026-45293HIGHCVSS 8.6EG 8.62026-07-28
WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulese…
- CVE-2026-40187HIGHCVSS 8.6EG 8.62026-07-07
In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the VFS `/etemplates` mount. The `Widget::expand_name()` method…
- CVE-2026-42079HIGHCVSS 8.6EG 8.62026-05-04
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched …
- CVE-2026-73248HIGHCVSS 8.5EG 8.52026-08-11
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inheri…
- CVE-2024-42002HIGHCVSS 8.4EG 8.42026-09-28
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulne…
- CVE-2026-8914HIGHCVSS 8.4EG 8.42026-06-05
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user …
- CVE-2019-9507HIGHCVSS 8.3EG 8.32020-03-30
The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed a…
- CVE-2020-6650HIGHCVSS 8.3EG 8.32020-03-23
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update…
- CVE-2026-13048HIGHCVSS 8.2EG 8.22026-08-13
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the ca…
- CVE-2026-79678HIGHCVSS 8.1EG 8.12026-09-07
A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated I…
- CVE-2026-29091HIGHCVSS 8.1EG 8.12026-03-06
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was discovered in the locutus project, specifically within the call_user_func_array fu…
Map vulnerabilities like CWE-95 to your infrastructure
EchelonGraph correlates every CVE — across CWE-95 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →