CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,465 vulnerabilities with CWE-94
CVE-2026-3946 LOW
PHPEMS 11.0 - Cross-Site Scripting via askcontent Parameter
CVSS 3.5
CVE-2026-20892 HIGH
MR-GM5L-S1 & MR-GM5A-L1 - Command Injection
CVSS 7.2
CVE-2026-30960 CRITICAL
rssn < 0.2.9 - Arbitrary Code Execution via JIT Compilation Engine
CVE-2026-2273 HIGH
Engineering Workstation - Code Injection
CVE-2026-30887 CRITICAL
OneUptime <10.0.18 - Command Injection
CVSS 9.9
CVE-2026-3819 LOW
SourceCodester Resort Reservation System 1.0 - XSS
CVSS 3.5
CVE-2026-3812 MEDIUM
itsourcecode Payroll Management System 1.0 - XSS
CVSS 4.3
CVE-2026-3766 LOW
SourceCodester Pharmacy System 1.0 - XSS
CVSS 3.5
CVE-2026-3763 MEDIUM
Simple Flight Ticket Booking System 1.0 - XSS
CVSS 4.3
CVE-2026-3743 LOW
YiFang CMS 2.0.5 - Cross-Site Scripting via Name Argument in Single Page Group Update
CVSS 3.5
CVE-2026-3742 LOW
YiFang CMS 2.0.5 - Cross-Site Scripting via Title Argument in update Function
CVSS 3.5
CVE-2026-3741 LOW
YiFang CMS 2.0.5 - Cross-Site Scripting via update Function in admin/D_friendLink.php
CVSS 3.5
CVE-2026-3721 LOW
SmartAdmin < 3.29 - Stored Cross-Site Scripting in Help Documentation Module
CVSS 3.5
CVE-2026-3720 LOW
1024-lab/lab1024 SmartAdmin <3.29 - XSS
CVSS 3.5
CVE-2026-3716 LOW
Wavlink WL-WN579X3-C 231124 - Cross-Site Scripting via Hostname Parameter in adm.cgi
CVSS 2.4
CVE-2026-3702 MEDIUM
SourceCodester Loan Management System 1.0 - XSS
CVSS 4.3
CVE-2026-3352 HIGH
Easy PHP Settings Plugin <1.0.4 - Code Injection
CVSS 7.2
CVE-2026-29075 HIGH
mesa < 3.5.0 - Remote Code Execution via benchmarks.yml Workflow
CVSS 8.3
CVE-2026-2830 MEDIUM
WP All Import <= 4.0.0 - Unauthenticated Reflected XSS via Filepath Parameter
CVSS 6.1
CVE-2026-29039 HIGH
changedetection.io <0.54.4 - Info Disclosure
CVSS 7.5
CVE-2026-28801 MEDIUM
Natro Macro <1.1.0 - Code Injection
CVSS 6.6
CVE-2026-25888 HIGH
Chartbrew < 4.8.1 - Remote Code Execution via Vulnerable API
CVSS 8.8
CVE-2026-25887 HIGH
Chartbrew < 4.8.1 - Remote Code Execution via MongoDB Dataset Query
CVSS 7.2
CVE-2026-3610 MEDIUM
HSC Cybersecurity Mailinspector <5.3.2-3 - XSS
CVSS 4.3
CVE-2026-28134 HIGH
Crocoblock JetEngine <=3.7.2 - Code Injection
CVSS 8.5
Details
Vulnerabilities 6,465
Exploit Likelihood Medium