CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,714 vulnerabilities with CWE-94
CVE-2026-7466 HIGH
AgentFlow Arbitrary Python Pipeline Execution via pipeline_path
CVSS 8.8
CVE-2026-7390 LOW
SourceCodester Pharmacy Sales and Inventory System index.php customer cross site scripting
CVSS 3.5
CVE-2026-7388 MEDIUM
EyouCMS Template File FilemanagerLogic.php editFile code injection
CVSS 4.7
CVE-2026-38992 CRITICAL
Cockpit < 2.14.0 - Remote Code Execution via Filter Parameter MongoLite $func Operator
CVSS 9.8
CVE-2026-7297 LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting
CVSS 2.4
CVE-2026-7296 LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting
CVSS 2.4
CVE-2026-7295 LOW
SourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting
CVSS 2.4
CVE-2026-7294 LOW
SourceCodester Pizzafy Ecommerce System index.php save_settings cross site scripting
CVSS 2.4
CVE-2026-27760 HIGH
OpenCATS PHP Code Injection via installer AJAX endpoint
CVSS 8.1
CVE-2026-7281 LOW
SourceCodester Pharmacy Sales and Inventory System index.php supplier cross site scripting
CVSS 2.4
CVE-2026-7269 LOW
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 2.4
CVE-2026-7230 MEDIUM
SourceCodester Safety Anger Pad cross site scripting
CVSS 4.3
CVE-2026-40967 HIGH
Spring AI 1.0.0-1.0.5 - Code Injection
CVSS 8.6
CVE-2026-7222 LOW
code-projects Coaching Management System Complaint Form complaint.php cross site scripting
CVSS 3.5
CVE-2026-7200 MEDIUM
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 4.3
CVE-2026-7191 HIGH
Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS
CVSS 7.2
CVE-2026-7129 MEDIUM
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
CVSS 4.3
CVE-2026-7116 MEDIUM
code-projects Employee Management System mark.php cross site scripting
CVSS 4.3
CVE-2026-7110 LOW
code-projects Invoice System in Laravel item cross site scripting
CVSS 3.5
CVE-2026-7095 MEDIUM
code-projects Employee Management System edit.php cross site scripting
CVSS 4.3
CVE-2026-7090 LOW
code-projects Chat System send_message.php cross site scripting
CVSS 2.4
CVE-2026-7089 MEDIUM
code-projects Home Service System Appointment Booking booking.php cross site scripting
CVSS 4.3
CVE-2026-7027 LOW
D-Link DSL-2740R Wireless Setup Section cross site scripting
CVSS 2.4
CVE-2026-7026 MEDIUM
D-Link DGS-3420 System Information Settings cross site scripting
CVSS 4.5
CVE-2026-7016 LOW
MaxSite CMS ushki Plugin cross site scripting
CVSS 2.4
Details
Vulnerabilities 6,714
Exploit Likelihood Medium