CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,463 vulnerabilities with CWE-94
CVE-2026-6623 LOW
BichitroGan ISP Billing Software Profile users-view cross site scripting
CVSS 2.4
CVE-2026-6622 LOW
BichitroGan ISP Billing Software Customer edit cross site scripting
CVSS 2.4
CVE-2026-6621 HIGH
1024bit extend-deep index.js prototype pollution
CVSS 7.3
CVE-2026-6619 LOW
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
CVSS 3.5
CVE-2026-41282 MEDIUM
ProjectDiscovery Nuclei <3.8.0 - DSL Injection
CVSS 4.0
CVE-2026-6603 HIGH
modelscope agentscope _python.py execute_shell_command code injection
CVSS 7.3
CVE-2026-6600 LOW
langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting
CVSS 3.5
CVE-2026-6594 HIGH
brikcss merge prototype pollution
CVSS 7.3
CVE-2026-6593 LOW
ComfyUI View Endpoint server.py cross site scripting
CVSS 3.5
CVE-2026-6592 LOW
ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting
CVSS 3.5
CVE-2026-6559 MEDIUM
Wavlink WL-WN579A3 login.cgi sub_401F80 cross site scripting
CVSS 4.3
CVE-2026-41242 CRITICAL
protobufjs Type Fields - Arbitrary Code Execution
CVSS 9.8
CVE-2026-40342 CRITICAL
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
CVSS 9.9
CVE-2026-6493 LOW
lukevella rallly Reset Password reset-password-form.tsx cross site scripting
CVSS 3.5
CVE-2026-6486 LOW
classroombookings User Display Name layout.php read cross site scripting
CVSS 3.5
CVE-2026-40322 CRITICAL
SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE
CVSS 9.0
CVE-2026-40316 HIGH
OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow
CVSS 8.8
CVE-2026-33435 HIGH
Weblate: Remote code execution during backup restoration
CVSS 8.0
CVE-2026-30993 CRITICAL
Slah CMS <=1.5.0 session() - Remote Code Execution
CVSS 9.8
CVE-2026-39842 CRITICAL
OpenRemote is Vulnerable to Expression Injection
CVSS 9.9
CVE-2026-1509 MEDIUM
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution
CVSS 5.4
CVE-2026-25125 MEDIUM
October CMS: Environment Variable Exfiltration via INI Parser Interpolation
CVSS 4.9
CVE-2026-2582 MEDIUM
Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution
CVSS 6.5
CVE-2026-40288 CRITICAL
PraisonAI: Critical RCE via `type: job` workflow YAML
CVSS 9.8
CVE-2026-40287 HIGH
PraisonAI has RCE via Automatic tools.py Import
CVSS 8.4
Details
Vulnerabilities 6,463
Exploit Likelihood Medium