CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
5,811 vulnerabilities with CWE-94
CVE-2026-3819
LOW
SourceCodester Resort Reservation System 1.0 - XSS
CVSS 3.5
CVE-2026-3812
MEDIUM
itsourcecode Payroll Management System 1.0 - XSS
CVSS 4.3
CVE-2026-3766
LOW
SourceCodester Pharmacy System 1.0 - XSS
CVSS 3.5
CVE-2026-3763
MEDIUM
Simple Flight Ticket Booking System 1.0 - XSS
CVSS 4.3
CVE-2026-3743
LOW
YiFang CMS 2.0.5 - XSS
CVSS 3.5
CVE-2026-3742
LOW
YiFang CMS 2.0.5 - XSS
CVSS 3.5
CVE-2026-3741
LOW
YiFang CMS 2.0.5 - XSS
CVSS 3.5
CVE-2026-3721
LOW
1024-lab SmartAdmin <3.29 - XSS
CVSS 3.5
CVE-2026-3720
LOW
1024-lab/lab1024 SmartAdmin <3.29 - XSS
CVSS 3.5
CVE-2026-3716
LOW
Wavlink WL-WN579X3-C 231124 - XSS
CVSS 2.4
CVE-2026-3702
MEDIUM
SourceCodester Loan Management System 1.0 - XSS
CVSS 4.3
CVE-2026-3352
HIGH
Easy PHP Settings Plugin <1.0.4 - Code Injection
CVSS 7.2
CVE-2026-29075
HIGH
Mesa <=3.5.0 - Code Injection
CVSS 8.3
CVE-2026-2830
MEDIUM
WP All Import <=4.0.0 - XSS
CVSS 6.1
CVE-2026-29039
changedetection.io <0.54.4 - Info Disclosure
CVE-2026-28801
MEDIUM
Natro Macro <1.1.0 - Code Injection
CVSS 6.6
CVE-2026-25888
HIGH
Chartbrew <4.8.1 - RCE
CVSS 8.8
CVE-2026-25887
HIGH
Chartbrew <4.8.1 - RCE
CVSS 7.2
CVE-2026-3610
MEDIUM
HSC Cybersecurity Mailinspector <5.3.2-3 - XSS
CVSS 4.3
CVE-2025-70995
HIGH
Aranda Service Desk 8.6 - Authenticated RCE
CVSS 8.8
CVE-2026-28134
HIGH
Crocoblock JetEngine <=3.7.2 - Code Injection
CVSS 8.5
CVE-2026-27984
CRITICAL
Widget Options <=4.1.3 - Code Injection
CVSS 9.0
CVE-2026-22390
Builderall Builder for WordPress <=3.0.1 - Code Injection
CVE-2026-28783
CRITICAL
Craft CMS <5.9.0-beta.1/4.17.0-beta.1 - RCE
CVSS 9.1
CVE-2026-23808
MEDIUM
Wireless Roaming Protocol - Auth Bypass
CVSS 5.4
Details
Vulnerabilities
5,811
Exploit Likelihood
Medium