CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,184 vulnerabilities with CWE-94
CVE-2026-7596
MEDIUM
nextlevelbuilder ui-ux-pro-max-skill Slide Generator generate-slide.py data.get cross site scripting
CVSS 4.3
CVE-2026-7595
MEDIUM
nextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator tailwind_config_gen.py _format_plugins code injection
CVSS 6.3
CVE-2026-7580
MEDIUM
Exiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injection
CVSS 5.3
CVE-2026-7508
MEDIUM
Bootstrap CMS Page Creation show.blade.php code injection
CVSS 6.3
CVE-2026-6543
HIGH
Authenticated Remote Code Execution Vulnerability in Langflow Code Validation Endpoint
CVSS 8.8
CVE-2026-7501
LOW
LinkStackOrg LinkStack UserController.php editPage cross site scripting
CVSS 3.5
CVE-2026-7401
MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting
CVSS 4.3
CVE-2026-34965
HIGH
Cockpit CMS Authenticated Remote Code Execution via Collections
CVSS 8.8
CVE-2026-7466
HIGH
AgentFlow Arbitrary Python Pipeline Execution via pipeline_path
CVSS 8.8
CVE-2026-7390
LOW
SourceCodester Pharmacy Sales and Inventory System index.php customer cross site scripting
CVSS 3.5
CVE-2026-7388
MEDIUM
EyouCMS Template File FilemanagerLogic.php editFile code injection
CVSS 4.7
CVE-2026-7297
LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting
CVSS 2.4
CVE-2026-7296
LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting
CVSS 2.4
CVE-2026-7295
LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting
CVSS 2.4
CVE-2026-7294
LOW
SourceCodester Pizzafy Ecommerce System index.php save_settings cross site scripting
CVSS 2.4
CVE-2026-27760
HIGH
OpenCATS PHP Code Injection via installer AJAX endpoint
CVSS 8.1
CVE-2026-7281
LOW
SourceCodester Pharmacy Sales and Inventory System index.php supplier cross site scripting
CVSS 2.4
CVE-2026-7269
LOW
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 2.4
CVE-2026-7230
MEDIUM
SourceCodester Safety Anger Pad cross site scripting
CVSS 4.3
CVE-2026-40967
HIGH
Spring AI 1.0.0-1.0.5 - Code Injection
CVSS 8.6
CVE-2026-7222
LOW
code-projects Coaching Management System Complaint Form complaint.php cross site scripting
CVSS 3.5
CVE-2026-7200
MEDIUM
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 4.3
CVE-2026-7191
HIGH
Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS
CVSS 7.2
CVE-2026-7129
MEDIUM
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 4.3
CVE-2026-7116
MEDIUM
code-projects Employee Management System mark.php cross site scripting
CVSS 4.3
Details
Vulnerabilities
6,184
Exploit Likelihood
Medium