CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,710 vulnerabilities with CWE-94
CVE-2026-15698 MEDIUM
kofrasa mingo Update API updateMany prototype pollution
CVSS 6.3
CVE-2026-15697 MEDIUM
svgdotjs svg.js npm Package API EventTarget.on prototype pollution
CVSS 6.3
CVE-2026-15678 LOW
code-projects Online Job Portal DetailJob.php cross site scripting
CVSS 3.5
CVE-2026-15607 MEDIUM
tanstack db Alias Path select.ts select prototype pollution
CVSS 4.3
CVE-2026-15598 MEDIUM
antv layout object.js setNestedValue prototype pollution
CVSS 6.3
CVE-2026-15596 MEDIUM
SourceCodester Class and Exam Timetabling System subject.php cross site scripting
CVSS 4.3
CVE-2026-15595 MEDIUM
SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting
CVSS 4.3
CVE-2026-55773 HIGH
CedarJava has a policy injection vulnerability
CVSS 8.8
CVE-2026-55771 HIGH
CedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities
CVSS 8.8
CVE-2026-6875 CRITICAL
Sandbox Escape in ServiceNow AI Platform
CVE-2026-12257 CRITICAL
Remote code execution in Mura Software’s CMS
CVE-2026-57811 CRITICAL
WordPress Realtyna Organic IDX plugin plugin <= 5.2.0 - Remote Code Execution (RCE) vulnerability
CVSS 10.0
CVE-2026-13014 CRITICAL
Thales CERT Suspicious <= 1.3.4 - Unauthenticated Remote Code Execution
CVE-2026-14453 CRITICAL
A user with low privileges can inject SSTI templates that can lead to RCE in open-tickets
CVSS 9.6
CVE-2026-15538 MEDIUM
primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
CVSS 6.3
CVE-2026-15533 MEDIUM
DedeCMS Column Management search.php code injection
CVSS 4.7
CVE-2026-15532 LOW
SourceCodester Online Book Store System User Management cross site scripting
CVSS 2.4
CVE-2026-15512 MEDIUM
pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection
CVSS 6.3
CVE-2026-15505 LOW
vnotex vnote YAML Frontmatter markdownit.js cross site scripting
CVSS 3.5
CVE-2026-15497 HIGH
SonicCloudOrg sonic-agent JWT Authentication Filter ExchangeController.java code injection
CVSS 7.3
CVE-2026-15493 LOW
Akpali9 Attendance-Management-System absent.php cross site scripting
CVSS 3.5
CVE-2026-15492 MEDIUM
igweze wizgrade studentConductManager.php cross site scripting
CVSS 4.3
CVE-2026-61447 CRITICAL
PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
CVSS 10.0
CVE-2026-13353 HIGH
WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter
CVSS 8.8
CVE-2026-61450 MEDIUM
Grav before 2.0.2 Config Exfiltration via offsetGet Filter
CVSS 6.5
Details
Vulnerabilities 6,710
Exploit Likelihood Medium