CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,712 vulnerabilities with CWE-94
CVE-2026-55895 HIGH
Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename
CVSS 7.8
CVE-2026-56049 HIGH
WordPress Post Snippets plugin <= 4.0.19 - Remote Code Execution (RCE) vulnerability
CVSS 8.5
CVE-2026-54823 CRITICAL
WordPress Widget Options plugin <= 4.2.3 - Remote Code Execution (RCE) vulnerability
CVSS 9.9
CVE-2026-1606 MEDIUM
Improper Control of Generation of Code ('Code Injection') in GitLab
CVSS 4.3
CVE-2026-55570 CRITICAL
SiYuan < 3.7.0 - Electron Remote Code Execution via data-obj XSS
CVSS 9.0
CVE-2026-44016 HIGH
Docling: Unsafe Playwright-based HTML Rendering
CVSS 8.2
CVE-2026-12242 HIGH
AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute
CVSS 8.8
CVE-2026-53753 CRITICAL
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVSS 9.8
CVE-2026-48519 CRITICAL
Langflow: Unauthenticated RCE in Shareable Playgrounds
CVSS 9.6
CVE-2026-44959 HIGH
Revive Adserver < 6.0.6 - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-34916 HIGH
Revive Adserver < 6.0.6 - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-12866 CRITICAL
Expr-eval - Improper Control of Generation of Code ('Code Injection')
CVSS 9.8
CVE-2026-41523 HIGH
vLLM < 0.22.0 Activation Function Loading - Unauthenticated Code Execution
CVSS 7.5
CVE-2026-55388 HIGH
piscina: Prototype Pollution Gadget → RCE via inherited options.filename
CVSS 8.1
CVE-2026-54271 HIGH
protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
CVSS 8.2
CVE-2026-10789 CRITICAL
Autodesk Fusion MCP Extension - Arbitrary Code Execution
CVSS 9.6
CVE-2026-9072 HIGH
IBM i WebSphere Web Server Plug-in - Remote Code Execution and Denial of Service
CVSS 8.1
CVE-2026-8858 HIGH
IBM i WebSphere Web Server Plug-in - Remote Code Execution and Denial of Service
CVSS 7.5
CVE-2026-50178 HIGH
Angular: Remote Code Execution via JSDoc Hover Command Injection in VS Code Angular Language Service Extension
CVSS 8.8
CVE-2026-49241 HIGH
Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code Extension
CVSS 8.8
CVE-2026-56446 HIGH
Authenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISP
CVSS 7.2
CVE-2026-10561 CRITICAL
Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection
CVSS 10.0
CVE-2026-12822 MEDIUM
langflow-ai langflow Bundle URL Loader code injection
CVSS 5.3
CVE-2026-12811 MEDIUM
kortix-ai suna Auth Endpoint page.tsx router.push cross site scripting
CVSS 4.3
CVE-2026-56382 HIGH
Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController
CVSS 7.2
Details
Vulnerabilities 6,712
Exploit Likelihood Medium