CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,488 vulnerabilities with CWE-94
CVE-2025-12299 MEDIUM
Simple Food Ordering System 1.0 - Cross-Site Scripting via pname/category/price Parameters
CVSS 4.3
CVE-2025-12298 MEDIUM
Simple Food Ordering System 1.0 - Cross-Site Scripting via pname Parameter in editcategory.php
CVSS 4.3
CVE-2025-12290 MEDIUM
Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0 - XSS
CVSS 4.3
CVE-2025-12289 MEDIUM
Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0 - XSS
CVSS 4.3
CVE-2025-12282 LOW
Client Details System 1.0 - Cross-Site Scripting in /admin/manage-users.php
CVSS 2.4
CVE-2025-12281 LOW
Client Details System 1.0 - Cross-Site Scripting in /admin/clientview.php
CVSS 2.4
CVE-2025-12280 LOW
Client Details System 1.0 - Cross-Site Scripting in /update-clients.php
CVSS 2.4
CVE-2025-12279 LOW
Client Details System 1.0 - Cross-Site Scripting in /welcome.php
CVSS 2.4
CVE-2025-12269 LOW
LearnHouse < 2025-09-21 - Cross-Site Scripting in Account Setting Page
CVSS 3.5
CVE-2025-12267 MEDIUM
abhicodebox ModernShop <20250922 - XSS
CVSS 4.3
CVE-2025-12266 MEDIUM
Zytec Dalian Zhuoyun Technology Central Authentication Service <202...
CVSS 6.3
CVE-2025-12264 LOW
Wisencode < 20251012 - Cross-Site Scripting via Message Parameter in Support Ticket Handler
CVSS 3.5
CVE-2025-12251 LOW
OpenWGA 7.11.12 Build 737 - Cross-Site Scripting in Admin UI
CVSS 3.5
CVE-2025-12246 MEDIUM
chatwoot < 4.7.0 - Cross-Site Scripting via IframeLoader Link Argument
CVSS 4.3
CVE-2025-12244 MEDIUM
Simple E-Banking System 1.0 - Cross-Site Scripting via Username Parameter in Register Page
CVSS 4.3
CVE-2025-12231 LOW
projectworlds Expense Management System 1.0 - Cross-Site Scripting in Expense Categories Page
CVSS 2.4
CVE-2025-12230 LOW
projectworlds Expense Management System 1.0 - Cross-Site Scripting in Currency Page
CVSS 2.4
CVE-2025-12229 LOW
projectworlds Expense Management System 1.0 - Cross-Site Scripting in Roles Page
CVSS 2.4
CVE-2025-12228 LOW
projectworlds Expense Management System 1.0 - Cross-Site Scripting in Users Page
CVSS 2.4
CVE-2025-12227 LOW
projectworlds Gate Pass Management System 1.0 - Cross-Site Scripting in /add-pass.php
CVSS 3.5
CVE-2025-12224 LOW
php-business-website <10677743a8dfc281f85291a27cf63a0bce043c24 - XSS
CVSS 3.5
CVE-2025-62959 CRITICAL
videowhisper Paid Videochat Turnkey Site <7.3.22 - Code Injection
CVSS 9.1
CVE-2025-8483 MEDIUM
The Discussion Board - WordPress Forum Plugin <2.5.5 - RCE
CVSS 6.3
CVE-2025-61136 HIGH
axewater sharewarez <2.4.3 - Host Header Injection
CVSS 7.1
CVE-2025-62023 CRITICAL
s2Member <= 250905 - Remote Code Execution
CVSS 9.0
Details
Vulnerabilities 6,488
Exploit Likelihood Medium