CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,184 vulnerabilities with CWE-94
CVE-2026-7110 LOW
code-projects Invoice System in Laravel item cross site scripting
CVSS 3.5
CVE-2026-7095 MEDIUM
code-projects Employee Management System edit.php cross site scripting
CVSS 4.3
CVE-2026-7090 LOW
code-projects Chat System send_message.php cross site scripting
CVSS 2.4
CVE-2026-7089 MEDIUM
code-projects Home Service System Appointment Booking booking.php cross site scripting
CVSS 4.3
CVE-2026-7027 LOW
D-Link DSL-2740R Wireless Setup Section cross site scripting
CVSS 2.4
CVE-2026-7026 MEDIUM
D-Link DGS-3420 System Information Settings cross site scripting
CVSS 4.5
CVE-2026-7016 LOW
MaxSite CMS ushki Plugin cross site scripting
CVSS 2.4
CVE-2026-7015 LOW
MaxSite CMS Guestbook Plugin cross site scripting
CVSS 2.4
CVE-2026-7014 LOW
MaxSite CMS down_count Plugin cross site scripting
CVSS 2.4
CVE-2026-7013 LOW
MaxSite CMS mail_send Plugin cross site scripting
CVSS 2.4
CVE-2026-7012 LOW
MaxSite CMS Redirect Plugin cross site scripting
CVSS 2.4
CVE-2026-7011 LOW
MaxSite CMS Antispam Plugin plugin_antispam cross site scripting
CVSS 2.4
CVE-2026-7001 LOW
Datacom DM4100 Ethernet Configuration cross site scripting
CVSS 2.4
CVE-2026-7000 LOW
Datacom DM4100 VLAN Page cross site scripting
CVSS 2.4
CVE-2026-6999 LOW
BIVOCOM TR321 Wireless Setting cross site scripting
CVSS 2.4
CVE-2026-6998 LOW
BDCOM P3310D New RMON Statistics cross site scripting
CVSS 2.4
CVE-2026-6997 LOW
BDCOM P3310D New RMON History cross site scripting
CVSS 2.4
CVE-2026-6996 LOW
BDCOM P3310D rmon event Tab cross site scripting
CVSS 2.4
CVE-2026-6995 LOW
BDCOM P3310D New User index.asp cross site scripting
CVSS 2.4
CVE-2026-6990 LOW
projeto-siga novo cross site scripting
CVSS 3.5
CVE-2026-6951 CRITICAL
Simple-git < 3.36.0 - Remote Code Execution
CVSS 9.8
CVE-2026-41414 HIGH
Skim: Arbitrary code execution via pull_request_target fork checkout in pr.yml
CVSS 7.4
CVE-2026-41044 HIGH
Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
CVSS 8.8
CVE-2026-40466 HIGH
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
CVSS 8.8
CVE-2026-41138 HIGH
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas.
CVSS 8.8
Details
Vulnerabilities 6,184
Exploit Likelihood Medium