CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,465 vulnerabilities with CWE-94
CVE-2026-26831 CRITICAL
textract through 2.5.0 - Command Injection
CVSS 9.8
CVE-2026-26830 CRITICAL
pdf-image through 2.0.0 - Command Injection
CVSS 9.8
CVE-2026-33336 HIGH
Vikunja Desktop vulnerable to Remote Code Execution via same-window navigation
CVSS 8.8
CVE-2026-33334 CRITICAL
Vikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegration
CVSS 9.6
CVE-2026-33310 HIGH
Intake <2.0.9 Parameter Defaults - Command Injection
CVSS 8.8
CVE-2026-33309 CRITICAL
Langflow 1.2.0-1.8.1 v2 File Upload - Arbitrary File Write
CVSS 9.9
CVE-2026-4745 CRITICAL
Arbitrary Code Execution via Crafted Bytecode in dendibakh/perf-ninja
CVE-2026-4626 LOW
projectworlds Lawyer Management System lawyer_booking.php cross site scripting
CVSS 3.5
CVE-2026-4616 LOW
bolo-blog Article Title article cross site scripting
CVSS 2.4
CVE-2026-4681 CRITICAL
Critical Remote Code Execution vulnerability reported in Windchill
CVE-2026-32276 HIGH
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
CVSS 8.8
CVE-2026-4596 LOW
projectworlds Lawyer Management System 1.0 - XSS
CVSS 3.5
CVE-2026-4595 LOW
code-projects Exam Form Submission update_s6.php cross site scripting
CVSS 2.4
CVE-2026-24516 HIGH
DigitalOcean Droplet Agent - Command Injection
CVSS 8.8
CVE-2026-33479 HIGH
AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin
CVSS 8.8
CVE-2026-4578 LOW
code-projects Exam Form Submission update_s3.php cross site scripting
CVSS 2.4
CVE-2026-4577 LOW
code-projects Exam Form Submission update_s4.php cross site scripting
CVSS 2.4
CVE-2026-4576 LOW
code-projects Exam Form Submission update_s5.php cross site scripting
CVSS 2.4
CVE-2026-4575 LOW
code-projects Exam Form Submission update_s2.php cross site scripting
CVSS 2.4
CVE-2026-4564 MEDIUM
yangzongzhuan RuoYi Quartz Job job code injection
CVSS 4.7
CVE-2026-4557 MEDIUM
code-projects Exam Form Submission update_s1.php cross site scripting
CVSS 4.3
CVE-2026-4544 LOW
Wavlink WL-WN578W2 POST Request login.cgi cross site scripting
CVSS 2.4
CVE-2026-4515 MEDIUM
Foundation Agents MetaGPT operator.py code_generate code injection
CVSS 6.3
CVE-2026-4510 MEDIUM
PbootCMS Parameter MemberController.php alert_location cross site scripting
CVSS 4.3
CVE-2026-4004 MEDIUM
Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'task_id' Parameter
CVSS 6.5
Details
Vulnerabilities 6,465
Exploit Likelihood Medium