CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,714 vulnerabilities with CWE-94
CVE-2026-9566 MEDIUM
teableio teable Sign-up LoginPage.tsx cross site scripting
CVSS 4.3
CVE-2026-9170 CRITICAL
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected DOS and RCE.
CVSS 9.8
CVE-2026-8855 HIGH
IBM HTTP Server is affected by multiple vulnerabilities
CVSS 8.1
CVE-2026-8633 CRITICAL
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
CVSS 9.8
CVE-2026-44728 HIGH
Improper Control of Generation of Code when compiling specifically crafted malicious code with @babel/plugin-transform-modules-systemjs
CVSS 8.2
CVE-2026-9564 LOW
SourceCodester/oretnom23 Hospitals Patient Records Management System view_patient cross site scripting
CVSS 2.4
CVE-2026-42785 HIGH
OpenKM 6.3.12 Remote Code Execution via Administrative Scripting
CVSS 7.2
CVE-2026-9527 MEDIUM
itsourcecode Electronic Judging System judges.php cross site scripting
CVSS 4.3
CVE-2026-9520 MEDIUM
blitz-js blitz Sign-in LoginForm.tsx cross site scripting
CVSS 4.3
CVE-2026-9519 MEDIUM
stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site scripting
CVSS 4.3
CVE-2026-9518 MEDIUM
hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addStudent cross site scripting
CVSS 4.3
CVE-2026-24937 HIGH
WordPress Broadcast Live Video plugin < 7.1.3 - Remote Code Execution (RCE) vulnerability
CVSS 7.2
CVE-2026-9485 LOW
SourceCodester Student Grades Management System students.php cross site scripting
CVSS 3.5
CVE-2026-9471 LOW
yashpokharna2555 StudentManagementSystem student.php cross site scripting
CVSS 3.5
CVE-2026-9448 MEDIUM
code-projects Employee Management System applyleave.php cross site scripting
CVSS 4.3
CVE-2026-9419 MEDIUM
code-projects Employee Management System empproject.php cross site scripting
CVSS 4.3
CVE-2026-9418 MEDIUM
code-projects Employee Management System changepassemp.php cross site scripting
CVSS 4.3
CVE-2026-9417 MEDIUM
code-projects Employee Management System myprofileup.php cross site scripting
CVSS 4.3
CVE-2026-9416 MEDIUM
code-projects Employee Management System myprofile.php cross site scripting
CVSS 4.3
CVE-2026-9415 MEDIUM
code-projects Employee Management System eloginwel.php cross site scripting
CVSS 4.3
CVE-2026-9414 LOW
SourceCodester Indian Invoicing System Invoice Template Render Database-Backed add_order.php cross site scripting
CVSS 3.5
CVE-2026-9413 MEDIUM
SourceCodester Indian Invoicing System category.php cross site scripting
CVSS 4.3
CVE-2026-9377 LOW
SourceCodester SUP Online Shopping productedit.php cross site scripting
CVSS 2.4
CVE-2026-9357 LOW
vBulletin Login cross site scripting
CVSS 3.5
CVE-2026-9302 MEDIUM
546669204 vps-inventory-monitoring VpsTest Console VpsTest.php eval code injection
CVSS 6.3
Details
Vulnerabilities 6,714
Exploit Likelihood Medium