← Back
CWE-94

6,471 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (6,471)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sourcegraph
1Sourcegraph
Nov 21, 2024
Feb 18, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restric...Show more
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is patched in Sourcegraph version 3.37. As a workaround, ensure that requests to gitserver are properly protected.Show less
1Mingsoft
1Mcms
Nov 21, 2024
Feb 18, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
1Php Everywhere Project
1Php Everywhere
Nov 21, 2024
Feb 16, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.
1Php Everywhere Project
1Php Everywhere
Nov 21, 2024
Feb 16, 2022
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.
1Php Everywhere Project
1Php Everywhere
Nov 21, 2024
Feb 16, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.
1Magnolia Cms
1Magnolia Cms
Nov 21, 2024
Feb 11, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullna...Show more
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.Show less
1Samsung
1Bixby
Nov 21, 2024
Feb 11, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.
1Google
1Android
Nov 21, 2024
Feb 11, 2022
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.
1Apache
1Cassandra
Nov 21, 2024
Feb 11, 2022
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker...Show more
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would need to have enough permissions to create user defined functions in the cluster to be able to exploit this. Note that this configuration is documented as unsafe, and will continue to be considered unsafe after this CVE.Show less
1Blitzjs
2Blitz
Superjson
Feb 24, 2026
Feb 9, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior aut...Show more
superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or knowledge. The only requirement is that the server implements at least one endpoint which uses superjson during request processing. This has been patched in superjson 1.8.1. Users are advised to update. There are no known workarounds for this issue.Show less
3Debian
FedoraprojectSymfony
3Debian Linux
FedoraTwig
Nov 21, 2024
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions th...Show more
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.Show less
1Idreamsoft
1Icms
Nov 21, 2024
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
1Prestashop
1Prestashop
Nov 21, 2024
Jan 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is...Show more
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.Show less
1Jpress
1Jpress
Nov 21, 2024
Jan 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
1Jpress
1Jpress
Nov 21, 2024
Jan 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some...Show more
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.Show less
1Jpress
1Jpress
Nov 21, 2024
Jan 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious...Show more
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.Show less
1F5
1Nginx Controller Api Management
Nov 21, 2024
Jan 25, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript cod...Show more
On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1Apache
1Shenyu
Nov 21, 2024
Jan 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
1Mustache Project
1Mustache
Nov 21, 2024
Jan 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.
1Trendmicro
1Deep Security Agent
Nov 21, 2024
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of r...Show more
A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and unconfigured state in order to exploit this vulnerability.Show less