CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,184 vulnerabilities with CWE-94
CVE-2026-7596 MEDIUM
nextlevelbuilder ui-ux-pro-max-skill Slide Generator generate-slide.py data.get cross site scripting
CVSS 4.3
CVE-2026-7595 MEDIUM
nextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator tailwind_config_gen.py _format_plugins code injection
CVSS 6.3
CVE-2026-7580 MEDIUM
Exiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injection
CVSS 5.3
CVE-2026-7508 MEDIUM
Bootstrap CMS Page Creation show.blade.php code injection
CVSS 6.3
CVE-2026-6543 HIGH
Authenticated Remote Code Execution Vulnerability in Langflow Code Validation Endpoint
CVSS 8.8
CVE-2026-7501 LOW
LinkStackOrg LinkStack UserController.php editPage cross site scripting
CVSS 3.5
CVE-2026-7401 MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting
CVSS 4.3
CVE-2026-34965 HIGH
Cockpit CMS Authenticated Remote Code Execution via Collections
CVSS 8.8
CVE-2026-7466 HIGH
AgentFlow Arbitrary Python Pipeline Execution via pipeline_path
CVSS 8.8
CVE-2026-7390 LOW
SourceCodester Pharmacy Sales and Inventory System index.php customer cross site scripting
CVSS 3.5
CVE-2026-7388 MEDIUM
EyouCMS Template File FilemanagerLogic.php editFile code injection
CVSS 4.7
CVE-2026-7297 LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting
CVSS 2.4
CVE-2026-7296 LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting
CVSS 2.4
CVE-2026-7295 LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting
CVSS 2.4
CVE-2026-7294 LOW
SourceCodester Pizzafy Ecommerce System index.php save_settings cross site scripting
CVSS 2.4
CVE-2026-27760 HIGH
OpenCATS PHP Code Injection via installer AJAX endpoint
CVSS 8.1
CVE-2026-7281 LOW
SourceCodester Pharmacy Sales and Inventory System index.php supplier cross site scripting
CVSS 2.4
CVE-2026-7269 LOW
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 2.4
CVE-2026-7230 MEDIUM
SourceCodester Safety Anger Pad cross site scripting
CVSS 4.3
CVE-2026-40967 HIGH
Spring AI 1.0.0-1.0.5 - Code Injection
CVSS 8.6
CVE-2026-7222 LOW
code-projects Coaching Management System Complaint Form complaint.php cross site scripting
CVSS 3.5
CVE-2026-7200 MEDIUM
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 4.3
CVE-2026-7191 HIGH
Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS
CVSS 7.2
CVE-2026-7129 MEDIUM
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 4.3
CVE-2026-7116 MEDIUM
code-projects Employee Management System mark.php cross site scripting
CVSS 4.3
Details
Vulnerabilities 6,184
Exploit Likelihood Medium