CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,184 vulnerabilities with CWE-94
CVE-2026-5643 LOW
Cyber-III Student-Management-System Admin Add Endpoint notice.php cross site scripting
CVSS 2.4
CVE-2026-5631 HIGH
assafelovic gpt-researcher ws Endpoint server_utils.py extract_command_data code injection
CVSS 7.3
CVE-2026-5630 MEDIUM
assafelovic gpt-researcher Report API app.py cross site scripting
CVSS 4.3
CVE-2026-5625 MEDIUM
assafelovic gpt-researcher WebSocket researcher.py cross site scripting
CVSS 4.3
CVE-2026-5615 MEDIUM
givanz Vvvebjs File Upload Endpoint upload.php cross site scripting
CVSS 4.3
CVE-2026-5594 MEDIUM
premAI-io premsql followup.py eval code injection
CVSS 6.3
CVE-2026-5584 HIGH
Fosowl agenticSeek query Endpoint PyInterpreter.py PyInterpreter.execute code injection
CVSS 7.3
CVE-2026-5568 LOW
Akaunting Invoice/Billing cross site scripting
CVSS 3.5
CVE-2026-5562 HIGH
provectus kafka-ui Endpoint testexecutions validateAccess code injection
CVSS 7.3
CVE-2026-5556 MEDIUM
badlogic pi-mono loader.ts discoverAndLoadExtensions code injection
CVSS 6.3
CVE-2026-5542 MEDIUM
code-projects Simple Laundry System Parameter modstaffinfo.php cross site scripting
CVSS 4.3
CVE-2026-5541 MEDIUM
code-projects Simple Laundry System Parameter modmemberinfo.php cross site scripting
CVSS 4.3
CVE-2026-5539 MEDIUM
code-projects Simple Laundry System Parameter modifymember.php cross site scripting
CVSS 4.3
CVE-2026-5533 MEDIUM
badlogic pi-mono SVG Artifact SvgArtifact.ts cross site scripting
CVSS 4.3
CVE-2026-3309 MEDIUM
ProfilePress < 4.16.11 - Arbitrary Shortcode Execution
CVSS 6.5
CVE-2026-28797 HIGH
RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component
CVSS 8.8
CVE-2026-5468 LOW
Casdoor dangerouslySetInnerHTML cross site scripting
CVSS 3.5
CVE-2026-5370 LOW
krayin laravel-crm Activities Module/Notes inbox.spec.ts composeMail cross site scripting
CVSS 3.5
CVE-2026-34725 HIGH
dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration
CVSS 8.2
CVE-2026-5332 LOW
Xiaopi Panel WAF Firewall demo.php cross site scripting
CVSS 3.5
CVE-2026-2701 CRITICAL
RCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)
CVSS 9.1
CVE-2026-5325 LOW
SourceCodester Simple Customer Relationship Management System Create Ticket create-ticket.php cross site scripting
CVSS 3.5
CVE-2026-1540 HIGH
Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution
CVSS 7.2
CVE-2026-5319 MEDIUM
itsourcecode Payroll Management System navbar.php cross site scripting
CVSS 4.3
CVE-2026-30643 CRITICAL
DedeCMS 5.7.118 - Code Injection
CVSS 9.8
Details
Vulnerabilities 6,184
Exploit Likelihood Medium