CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,488 vulnerabilities with CWE-94
CVE-2025-12299
MEDIUM
Simple Food Ordering System 1.0 - Cross-Site Scripting via pname/category/price Parameters
CVSS 4.3
CVE-2025-12298
MEDIUM
Simple Food Ordering System 1.0 - Cross-Site Scripting via pname Parameter in editcategory.php
CVSS 4.3
CVE-2025-12290
MEDIUM
Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0 - XSS
CVSS 4.3
CVE-2025-12289
MEDIUM
Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0 - XSS
CVSS 4.3
CVE-2025-12282
LOW
Client Details System 1.0 - Cross-Site Scripting in /admin/manage-users.php
CVSS 2.4
CVE-2025-12281
LOW
Client Details System 1.0 - Cross-Site Scripting in /admin/clientview.php
CVSS 2.4
CVE-2025-12280
LOW
Client Details System 1.0 - Cross-Site Scripting in /update-clients.php
CVSS 2.4
CVE-2025-12279
LOW
Client Details System 1.0 - Cross-Site Scripting in /welcome.php
CVSS 2.4
CVE-2025-12269
LOW
LearnHouse < 2025-09-21 - Cross-Site Scripting in Account Setting Page
CVSS 3.5
CVE-2025-12267
MEDIUM
abhicodebox ModernShop <20250922 - XSS
CVSS 4.3
CVE-2025-12266
MEDIUM
Zytec Dalian Zhuoyun Technology Central Authentication Service <202...
CVSS 6.3
CVE-2025-12264
LOW
Wisencode < 20251012 - Cross-Site Scripting via Message Parameter in Support Ticket Handler
CVSS 3.5
CVE-2025-12251
LOW
OpenWGA 7.11.12 Build 737 - Cross-Site Scripting in Admin UI
CVSS 3.5
CVE-2025-12246
MEDIUM
chatwoot < 4.7.0 - Cross-Site Scripting via IframeLoader Link Argument
CVSS 4.3
CVE-2025-12244
MEDIUM
Simple E-Banking System 1.0 - Cross-Site Scripting via Username Parameter in Register Page
CVSS 4.3
CVE-2025-12231
LOW
projectworlds Expense Management System 1.0 - Cross-Site Scripting in Expense Categories Page
CVSS 2.4
CVE-2025-12230
LOW
projectworlds Expense Management System 1.0 - Cross-Site Scripting in Currency Page
CVSS 2.4
CVE-2025-12229
LOW
projectworlds Expense Management System 1.0 - Cross-Site Scripting in Roles Page
CVSS 2.4
CVE-2025-12228
LOW
projectworlds Expense Management System 1.0 - Cross-Site Scripting in Users Page
CVSS 2.4
CVE-2025-12227
LOW
projectworlds Gate Pass Management System 1.0 - Cross-Site Scripting in /add-pass.php
CVSS 3.5
CVE-2025-12224
LOW
php-business-website <10677743a8dfc281f85291a27cf63a0bce043c24 - XSS
CVSS 3.5
CVE-2025-62959
CRITICAL
videowhisper Paid Videochat Turnkey Site <7.3.22 - Code Injection
CVSS 9.1
CVE-2025-8483
MEDIUM
The Discussion Board - WordPress Forum Plugin <2.5.5 - RCE
CVSS 6.3
CVE-2025-61136
HIGH
axewater sharewarez <2.4.3 - Host Header Injection
CVSS 7.1
CVE-2025-62023
CRITICAL
s2Member <= 250905 - Remote Code Execution
CVSS 9.0
Details
Vulnerabilities
6,488
Exploit Likelihood
Medium