← Back
CWE-94

7,055 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,055)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.
1Sitos
1Sitos Six
Jun 17, 2026
Oct 7, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.
1Vbulletin
1Vbulletin
Jun 17, 2026
Oct 4, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
vBulletin through 5.5.4 mishandles custom avatars.
1Jenkins
1Script Security
Jun 17, 2026
Oct 1, 2019
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.
1Vbulletin
1Vbulletin
Jun 17, 2026
Sep 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
1Embedthis
1Goahead
Jun 17, 2026
Sep 20, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. Thi...Show more
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack.Show less
1Prise
1Adas
Jun 17, 2026
Sep 20, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote code execution.
1Atlassian
2Jira Data Center
Jira Server
Jun 17, 2026
Sep 19, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0...Show more
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allows remote attackers with Administrator permissions to gain remote code execution via a template injection vulnerability through the use of a crafted PUT request.Show less
1Advantech
1Webaccess
Jun 17, 2026
Sep 18, 2019
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash.
1Dell
2Rsa Identity Governance And Lifecycle
Rsa Via Lifecycle And Governance
Jun 17, 2026
Sep 11, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit...Show more
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain limited access to view or modify information on the Workflow system.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Sep 10, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed...Show more
SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and SAP-JEECOR (before versions 6.40, 7.0, 7.01), allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application.Show less
1Metagauss
1Profilegrid
Jun 17, 2026
Sep 3, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by...Show more
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.Show less
1Mongodb
1Mongodb
Jun 17, 2026
Aug 30, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user runnin...Show more
An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user running the utility. This issue MongoDB Server v4.0 versions prior to 4.0.11; MongoDB Server v3.6 versions prior to 3.6.14 and MongoDB Server v3.4 prior to 3.4.22.Show less
1Groundhogg
1Groundhogg
Jun 17, 2026
Aug 27, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
1Bbpress Move Topics Project
1Bbpress Move Topics
Nov 21, 2024
Aug 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
1Webmin
1Webmin
Jun 17, 2026
Aug 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used t...Show more
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users."Show less
1Google Forms Project
1Google Forms
Nov 21, 2024
Aug 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
1Oscommerce
1Oscommerce
Nov 21, 2024
Aug 22, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrar...Show more
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page. Remote authenticated administrators can upload new '.htaccess' files (e.g., omitting .php) and subsequently achieve arbitrary PHP code execution via a /catalog/admin/categories.php?cPath=&action=new_product URI.Show less