← Back
CWE-94

7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,044)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vanillaforums
1Vanilla
Nov 21, 2024
Nov 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vanilla 2.6.x before 2.6.4 allows remote code execution.
1Rainmachine
1Mini 8 Firmware
Jun 17, 2026
Nov 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.
11234n
1Minicms
Nov 21, 2024
Nov 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
1Redhat
2Cloudforms
Cloudforms Management Engine
Nov 21, 2024
Oct 31, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execut...Show more
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.Show less
1Doccms
1Doccms
Nov 21, 2024
Oct 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.
1Kibokolabs
1Arigato Autoresponder And Newsletter
Nov 21, 2024
Oct 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.
1S Cms
1S Cms
Nov 21, 2024
Oct 17, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt parameter.
1Asuswrt Merlin Project
14Rt Ac1900 Firmware
Rt Ac2900 FirmwareRt Ac3100 Firmware+11 more
Nov 21, 2024
Oct 15, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=...Show more
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code executionShow less
1Bagesoft
1Bagecms
Nov 21, 2024
Oct 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.
1Adbglobal
1Epicentro
Jun 17, 2026
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a manipulated POST request.
1Comsenz
1Duomicms
Nov 21, 2024
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
1Videowhisper
1Video Presentation
Nov 21, 2024
Oct 5, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated...Show more
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file containing PHP code.Show less
1Emerson
1Ams Device Manager
Nov 21, 2024
Oct 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.
1Hisiphp
1Hisiphp
Nov 21, 2024
Oct 1, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into app/admin/model/AdminPlugins.php.
1Otcms
1Otcms
Nov 21, 2024
Sep 23, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.
1Lg
1Supersign Cms
Nov 21, 2024
Sep 21, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
1Awesomemotive
1Duplicator
Feb 2, 2026
Sep 19, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup...Show more
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.Show less
1Moodle
1Moodle
Nov 21, 2024
Sep 17, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, i...Show more
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.Show less
4Apache
CanonicalDebian+1 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Nov 21, 2024
Sep 17, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
4Apache
CanonicalDebian+1 more
4Debian Linux
PdfinfoSpamassassin+1 more
Nov 21, 2024
Sep 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.