CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,184 vulnerabilities with CWE-94
CVE-2026-6619 LOW
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
CVSS 3.5
CVE-2026-41282 MEDIUM
ProjectDiscovery Nuclei <3.8.0 - DSL Injection
CVSS 4.0
CVE-2026-6603 HIGH
modelscope agentscope _python.py execute_shell_command code injection
CVSS 7.3
CVE-2026-6600 LOW
langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting
CVSS 3.5
CVE-2026-6594 HIGH
brikcss merge prototype pollution
CVSS 7.3
CVE-2026-6593 LOW
ComfyUI View Endpoint server.py cross site scripting
CVSS 3.5
CVE-2026-6592 LOW
ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting
CVSS 3.5
CVE-2026-6559 MEDIUM
Wavlink WL-WN579A3 login.cgi sub_401F80 cross site scripting
CVSS 4.3
CVE-2026-41242 CRITICAL
protobufjs has an arbitrary code execution issue
CVSS 9.8
CVE-2026-40342 CRITICAL
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
CVSS 9.9
CVE-2026-6493 LOW
lukevella rallly Reset Password reset-password-form.tsx cross site scripting
CVSS 3.5
CVE-2026-6486 LOW
classroombookings User Display Name layout.php read cross site scripting
CVSS 3.5
CVE-2026-40322 CRITICAL
SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE
CVSS 9.0
CVE-2026-40316 HIGH
OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow
CVSS 8.8
CVE-2026-33435 HIGH
Weblate: Remote code execution during backup restoration
CVSS 8.0
CVE-2026-30993 CRITICAL
Slah CMS <=1.5.0 - RCE
CVSS 9.8
CVE-2026-39842 CRITICAL
OpenRemote is Vulnerable to Expression Injection
CVSS 9.9
CVE-2026-1509 MEDIUM
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution
CVSS 5.4
CVE-2026-25125 MEDIUM
October CMS: Environment Variable Exfiltration via INI Parser Interpolation
CVSS 4.9
CVE-2026-2582 MEDIUM
Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution
CVSS 6.5
CVE-2026-40288 CRITICAL
PraisonAI: Critical RCE via `type: job` workflow YAML
CVSS 9.8
CVE-2026-40287 HIGH
PraisonAI has RCE via Automatic tools.py Import
CVSS 8.4
CVE-2026-39421 MEDIUM
MaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotect
CVSS 6.3
CVE-2026-27675 LOW
Code Injection vulnerability in SAP Landscape Transformation
CVSS 2.0
CVE-2026-27674 MEDIUM
Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)
CVSS 6.1
Details
Vulnerabilities 6,184
Exploit Likelihood Medium