← Back
CWE-94

7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,044)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cim Project
1Cim
Jun 17, 2026
Feb 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs fun...Show more
install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs function that creates a .php file in the public folder.Show less
1Thinkcmf
1Thinkcmf
Jun 17, 2026
Feb 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injectio...Show more
ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.Show less
1Lcds
1Laquis Scada
Nov 21, 2024
Feb 5, 2019
N/A· v4
7.8 HIGH· v3
8.3 HIGH· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash...Show more
LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash.Show less
1Ibm
1Security Identity Manager
Jun 17, 2026
Feb 4, 2019
N/A· v4
6.2 MEDIUM· v3
4.6 MEDIUM· v2
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limi...Show more
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.Show less
1Thinkcmf
1Thinkcmf
Jun 17, 2026
Jan 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php...Show more
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.Show less
1Omron
1Cx Supervisor
Nov 21, 2024
Jan 22, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
1Prestashop
1Prestashop
Nov 21, 2024
Jan 15, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of at least a Salesman or higher privileges. The attacker can then inject...Show more
In the orders section of PrestaShop before 1.7.2.5, an attack is possible after gaining access to a target store with a user role with the rights of at least a Salesman or higher privileges. The attacker can then inject arbitrary PHP objects into the process and abuse an object chain in order to gain Remote Code Execution. This occurs because protection against serialized objects looks for a 0: followed by an integer, but does not consider 0:+ followed by an integer.Show less
1Woocommerce
1Woocommerce
Nov 21, 2024
Jan 15, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a...Show more
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically crafted string that will turn into a PHP object injection involving the includes/shortcodes/class-wc-shortcode-products.php WC_Shortcode_Products::get_products() use of cached queries within shortcodes.Show less
1Redhat
1Bodhi
Nov 21, 2024
Jan 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.
1Cisco
1Ip Phone 8800 Series Firmware
Nov 21, 2024
Jan 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device. The vulnerability exists because the softw...Show more
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device. The vulnerability exists because the software running on an affected device insufficiently validates user-supplied data. An attacker could exploit this vulnerability by persuading a user to click a malicious link provided to the user or through the interface of an affected device. A successful exploit could allow an attacker to execute arbitrary script code in the context of the user interface or access sensitive system-based information, which under normal circumstances should be prohibited.Show less
1Jpcert
1Logontracer
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
2Redhat
Xtermjs
2Openshift Container Platform
Xterm.js
Jun 17, 2026
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
1Sap
1Cloud Connector
Jun 17, 2026
Jan 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
1Sqla Yaml Fixtures Project
1Sqla Yaml Fixtures
Jun 17, 2026
Jan 3, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.
1Ucms Project
1Ucms
Nov 21, 2024
Dec 30, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
1Schneider Electric
1Evlink Parking Firmware
Jun 17, 2026
Dec 24, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable access with maximum privileges when a remote code execution is performed.
1Definitions Project
1Definitions
Nov 21, 2024
Dec 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.
1Traccar
1Server
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. Thi...Show more
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.Show less