CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,184 vulnerabilities with CWE-94
CVE-2026-6218
MEDIUM
aandrew-me ytDownloader Error Details Panel createTextNode cross site scripting
CVSS 4.3
CVE-2026-6216
LOW
DbGate SVG Icon String FontIcon.svelte cross site scripting
CVSS 3.5
CVE-2026-31048
CRITICAL
Pyro v3.x - Code Injection
CVSS 9.8
CVE-2026-29955
HIGH
KubePlus 4.14 - Command Injection
CVSS 8.8
CVE-2026-6184
LOW
code-projects Simple Content Management System welcome.php cross site scripting
CVSS 2.4
CVE-2026-6162
LOW
PHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scripting
CVSS 3.5
CVE-2026-6159
MEDIUM
code-projects Simple ChatBox Endpoint insert.php cross site scripting
CVSS 4.3
CVE-2026-6150
MEDIUM
code-projects Simple Laundry System checkupdatestatus.php cross site scripting
CVSS 4.3
CVE-2026-6125
MEDIUM
Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection
CVSS 6.3
CVE-2026-6110
HIGH
FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
CVSS 7.3
CVE-2026-6107
LOW
1Panel-dev MaxKB ChatHeadersMiddleware chat_headers_middleware.py cross site scripting
CVSS 3.5
CVE-2026-6106
LOW
1Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting
CVSS 3.5
CVE-2026-40158
HIGH
PraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonai
CVSS 8.6
CVE-2026-40156
HIGH
PraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVSS 7.8
CVE-2026-6035
MEDIUM
code-projects Vehicle Showroom Management System ServiceAndSalesReport.php cross site scripting
CVSS 4.3
CVE-2026-6034
MEDIUM
code-projects Vehicle Showroom Management System ProfitAndLossReport.php cross site scripting
CVSS 4.3
CVE-2026-6032
MEDIUM
code-projects Simple Laundry System checkcheckout.php cross site scripting
CVSS 4.3
CVE-2026-6003
LOW
code-projects Simple IT Discussion Forum user.php cross site scripting
CVSS 2.4
CVE-2026-5971
HIGH
FoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injection
CVSS 7.3
CVE-2026-5970
HIGH
FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection
CVSS 7.3
CVE-2026-30479
CRITICAL
OSGeo Project MapServer <8.0 - DLL Injection
CVSS 9.1
CVE-2026-5848
MEDIUM
jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection
CVSS 4.7
CVE-2026-5836
LOW
code-projects Online Shoe Store admin_product.php cross site scripting
CVSS 2.4
CVE-2026-5835
LOW
code-projects Online Shoe Store admin_football.php cross site scripting
CVSS 2.4
CVE-2026-5834
LOW
code-projects Online Shoe Store admin_running.php cross site scripting
CVSS 2.4
Details
Vulnerabilities
6,184
Exploit Likelihood
Medium