CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,474 vulnerabilities with CWE-94
CVE-2026-3028 MEDIUM
JEEWMS < 3.7 - Stored Cross-Site Scripting via Name Parameter in doAdd Function
CVSS 4.3
CVE-2026-3027 MEDIUM
JEEWMS < 3.7 - Cross-Site Scripting via UEditor getContent.jsp myEditor Parameter
CVSS 4.3
CVE-2026-2972 LOW
Smart-SSO < 2.1.1 - Stored Cross-Site Scripting in Role Edit Page
CVSS 2.4
CVE-2026-2971 MEDIUM
Smart-SSO < 2.1.1 - Cross-Site Scripting via redirectUri Parameter
CVSS 4.3
CVE-2026-2965 LOW
07FLYCMS 1.2.0-1.2.9 - Stored Cross-Site Scripting via SysModule Title Parameter
CVSS 2.4
CVE-2026-2964 MEDIUM
higuma web-audio-recorder-js 0.1/0.1.1 - Prototype Pollution
CVSS 5.0
CVE-2026-2947 LOW
rymcu forest <= 0.0.5 - Cross-Site Scripting in User Profile Handler
CVSS 3.5
CVE-2026-2946 LOW
rymcu forest < 0.0.5 - Cross-Site Scripting in XssUtils.replaceHtmlCode
CVSS 3.5
CVE-2026-2943 MEDIUM
SapneshNaik Student Management System - XSS
CVSS 4.3
CVE-2026-2939 LOW
itsourcecode Student Management System 1.0 - XSS
CVSS 2.4
CVE-2026-2934 LOW
YiFang CMS < 2.0.5 - Cross-Site Scripting via Name Parameter in Extended Management Module
CVSS 2.4
CVE-2026-2933 LOW
YiFang CMS < 2.0.5 - Cross-Site Scripting via Name Parameter in Extended Management Module
CVSS 2.4
CVE-2026-2932 LOW
YiFang CMS < 2.0.5 - Cross-Site Scripting via Extended Management Module
CVSS 2.4
CVE-2026-2897 LOW
funadmin < 7.1.0 - Cross-Site Scripting via Backend Interface Value Argument
CVSS 2.4
CVE-2026-27574 CRITICAL
OneUptime <=9.5.13 - Code Injection
CVSS 9.9
CVE-2026-27464 HIGH
Metabase <0.57.13/0.58.x-0.58.6 - Info Disclosure
CVSS 7.7
CVE-2026-26045 HIGH
Moodle 4.5.0-4.5.8 and 5.1.0-beta-5.1.1 - Authenticated Remote Code Execution via Backup Restore
CVSS 7.2
CVE-2026-2825 LOW
rachelos WeRSS we-mp-rss <=1.4.8 - XSS
CVSS 3.5
CVE-2026-26030 CRITICAL
Microsoft Semantic Kernel <1.39.4 - RCE
CVSS 9.9
CVE-2026-25755 HIGH
jsPDF < 4.2.0 - Code Injection via addJS Method
CVSS 8.1
CVE-2026-24764 LOW
OpenClaw <=2026.2.2 - Command Injection
CVSS 3.7
CVE-2026-25548 CRITICAL
InvoicePlane 1.7.0 - RCE via LFI & Log Poisoning
CVSS 9.1
CVE-2026-27174 CRITICAL
MajorDoMo - Unauthenticated Remote Code Execution via Admin Console Eval
CVSS 9.8
CVE-2026-2296 HIGH
Product Addons for Woocommerce 3.1.0 - Code Injection
CVSS 7.2
CVE-2026-2622 LOW
Blossom < 1.17.1 - Cross-Site Scripting in Article Title Handler
CVSS 3.5
Details
Vulnerabilities 6,474
Exploit Likelihood Medium