← Back
CWE-94

7,062 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,062)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simple Ads Manager Project
1Simple Ads Manager
Nov 21, 2024
Jun 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability classified as critical was found in Simple Ads Manager Plugin. This vulnerability affects unknown code. The manipulation leads to code injection. The attack can be initiated remotely.
1Automattic
1Vaultpress
Nov 21, 2024
Jun 23, 2022
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.
1Elefantcms
1Elefant Cms
Nov 21, 2024
Jun 20, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. The manipulation leads to code injection....Show more
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. The manipulation leads to code injection. The attack can be launched remotely. Upgrading to version 1.3.13 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Flatcore
1Flatcore Cms
Jun 17, 2026
Jun 16, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
1Memberhero
1Member Hero
Jun 17, 2026
Jun 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments...Show more
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.Show less
1Nuitka
1Nuitka
Jun 17, 2026
Jun 12, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Code Injection in GitHub repository nuitka/nuitka prior to 0.9.
1Nystudio107
1Seomatic
Jun 17, 2026
Jun 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.
1Convert Svg Core Project
1Convert Svg Core
Jun 17, 2026
Jun 10, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a...Show more
The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.Show less
1Diagrams
1Drawio
Jun 17, 2026
Jun 9, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.
1Metarhia
1Metacalc
Jun 17, 2026
Jun 8, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScrip...Show more
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.Show less
2Debian
Rubyonrails
2Active Storage
Debian Linux
Jun 17, 2026
May 26, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
3Debian
FedoraprojectSmarty
3Debian Linux
FedoraSmarty
Jun 17, 2026
May 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {bloc...Show more
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully trust template authors should upgrade to versions 3.1.45 or 4.1.1 to receive a patch for this issue. There are currently no known workarounds.Show less
1Google
1Tensorflow
Jun 17, 2026
May 21, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shel...Show more
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path was maintained for compatibility reasons as the maintainers had several test cases where numpy expressions were used as arguments. However, given that the tool is always run manually, the impact of this is still not severe. The maintainers have now removed the `safe=False` argument, so all parsing is done without calling `eval`. The patch is available in versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4.Show less
1Weintek
16Cmt Ctrl01 Firmware
Cmt Fhd FirmwareCmt G01 Firmware+13 more
Jun 17, 2026
May 16, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.
1Publify Project
1Publify
Jun 17, 2026
May 16, 2022
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Code Injection in GitHub repository publify/publify prior to 9.2.8.
1Ionizecms
1Ionize
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php.
1Pentest Collaboration Framework Project
1Pentest Collaboration Framework
Jun 17, 2026
May 11, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/.
1Ejointech
3Acom508 Firmware
Acom516 FirmwareAcom532 Firmware
Jun 17, 2026
May 9, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.
1Sourcegraph
1Sourcegraph
Jun 17, 2026
May 6, 2022
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows...Show more
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows Sourcegraph site admins to specify a `callsignCommand`, which is used to obtain the Phabricator metadata for a Gitolite repository. An administrator who is able to edit or add a Gitolite code host and has administrative access to Sourcegraph’s bundled Grafana instance can change this command arbitrarily and run it remotely. This grants direct access to the infrastructure underlying the Sourcegraph installation. The attack requires: site-admin privileges on the instance of Sourcegraph, Administrative privileges on the bundled Grafana monitoring instance, Knowledge of the gitserver IP address or DNS name (if running in Kubernetes). This can be found through Grafana. The issue is patched in version 3.38.0. You may disable Gitolite code hosts. We still highly encourage upgrading regardless of workarounds.Show less
1Fluxcd
3Flux2
Helm ControllerKustomize Controller
Jun 17, 2026
May 6, 2022
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Inj...Show more
Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Injection via malicious Kubeconfig. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. Workarounds include disabling functionality via Validating Admission webhooks by restricting users from setting the `spec.kubeConfig` field in Flux `Kustomization` and `HelmRelease` objects. Additional mitigations include applying restrictive AppArmor and SELinux profiles on the controller’s pod to limit what binaries can be executed. This vulnerability is fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0Show less