CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,712 vulnerabilities with CWE-94
CVE-2026-5366 CRITICAL
Git Argument Injection in prefecthq/prefect
CVSS 9.9
CVE-2026-36418 CRITICAL
JimuReport <= 2.3.4 - Remote Code Execution via Aviator Expression Injection
CVSS 9.1
CVE-2026-47103 CRITICAL
Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection
CVSS 9.8
CVE-2026-54816 HIGH
WordPress Advanced Ads plugin <= 2.0.21 - Remote Code Execution (RCE) vulnerability
CVSS 7.5
CVE-2026-49113 HIGH
WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerability
CVSS 8.5
CVE-2026-40783 CRITICAL
WordPress Blocksy Companion Pro plugin <= 2.1.37 - Remote Code Execution (RCE) vulnerability
CVSS 9.9
CVE-2026-25470 CRITICAL
WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.47 - Remote Code Execution (RCE) vulnerability
CVSS 10.0
CVE-2026-46851 HIGH
PeopleSoft Enterprise CS Campus Community 9.2.38 - Unauthenticated Remote Code Execution via HTTP
CVSS 8.1
CVE-2026-46850 CRITICAL
MySQL Shell 2026.2.0+9.6.1 - Authenticated Remote Code Execution via Shell for VS Code
CVSS 9.9
CVE-2026-24155 HIGH
Nvidia NeMo Framework - Improper Control of Generation of Code ('Code Injection')
CVSS 7.8
CVE-2026-49774 CRITICAL
WordPress RD Station plugin <= 5.6.0 - Remote Code Execution (RCE) vulnerability
CVSS 9.9
CVE-2026-48017 HIGH
DbGate: Remote Code Execution via functionName injection in loadReader endpoint
CVSS 8.8
CVE-2026-48836 CRITICAL
WordPress Easy Invoice plugin <= 2.1.19 - Remote Code Execution (RCE) vulnerability
CVSS 10.0
CVE-2026-48124 HIGH
Cursor Desktop sandbox escape via Claude hook configuration
CVE-2026-39465 CRITICAL
WordPress Responsive Slider by MetaSlider plugin <= 3.106.0 - Remote Code Execution (RCE) vulnerability
CVSS 9.1
CVE-2026-50880 CRITICAL
YouTransfer 1.0.6 - Remote Code Execution via Sendmail Transport Integration
CVSS 9.8
CVE-2026-50872 CRITICAL
fossar selfoss 2.20-SNAPSHOT - Remote Code Execution via Loopback Request Handling
CVSS 9.8
CVE-2026-50871 CRITICAL
kanishka-linux Reminiscence 0.3.0 - OS Command Injection via Media Archiving Pipeline
CVSS 9.8
CVE-2026-30120 CRITICAL
remotion-dev remotion v4.0.409 - Remote Code Execution
CVSS 9.8
CVE-2026-52704 CRITICAL
WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Remote Code Execution (RCE) vulnerability
CVSS 10.0
CVE-2026-11860 HIGH
Insecure Deserialisation via Plaintext HTTP leading to Remote Code Execution in Quick.CMS
CVE-2026-12209 MEDIUM
RubyLouvre avalon Template Filter index.js prototype pollution
CVSS 5.3
CVE-2026-12208 MEDIUM
jsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution
CVSS 5.3
CVE-2026-12202 LOW
Intelliants Subrion CMS Blocks Endpoint cross site scripting
CVSS 2.4
CVE-2026-12176 MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics index.php cross site scripting
CVSS 4.3
Details
Vulnerabilities 6,712
Exploit Likelihood Medium