CVEbaza.plCWE DictionaryCWE-94
Common Weakness Enumeration

CWE-94

Improper Control of Generation of Code ('Code Injection')

Category: BaseCVE: 7,409
Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVE vulnerabilities with CWE-94 (7,409)
10.0
CVSS
CRITICAL
CVE-2026-18885

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

pub. 2026-08-27
10.0
CVSS
CRITICAL
CVE-2026-6876

ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

pub. 2026-08-27
10.0
CVSS
CRITICAL
CVE-2026-76604

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.

pub. 2026-08-22
10.0
CVSS
CRITICAL
CVE-2026-76605

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

pub. 2026-08-22
10.0
CVSS
CRITICAL
CVE-2026-67364

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting an unauthenticated attacker inject arbitrary PHP that executes server-side. The CSRF token needed to reach the endpoint is itself disclosed anonymously via a separate task, so it provides no real protection. Exploitability requires the form to have a custom-PHP handler configured (a documented builder feature) referencing that shortcode, and no reCAPTCHA on the submit button.

pub. 2026-08-19
10.0
CVSS
CRITICAL
CVE-2026-73343

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

pub. 2026-08-18
10.0
CVSS
CRITICAL
CVE-2026-74253

Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.

pub. 2026-08-17
10.0
CVSS
CRITICAL
CVE-2026-73678

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/v1/settings/ endpoint, then POST a prompt directing the agent to invoke the scratchpad tool with arbitrary Python code, achieving full OS command execution as the user running the desktop application and enabling access to SSH keys, stored credentials, and environment secrets.

pub. 2026-08-14
10.0
CVSS
CRITICAL
CVE-2026-27544

Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.

pub. 2026-08-13
10.0
CVSS
CRITICAL
CVE-2026-61962

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

pub. 2026-08-13
10.0
CVSS
CRITICAL
CVE-2026-67282

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

pub. 2026-08-12
10.0
CVSS
CRITICAL
CVE-2026-73299

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5.

pub. 2026-08-12
10.0
CVSS
CRITICAL
CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

pub. 2026-08-11
10.0
CVSS
CRITICAL
CVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

pub. 2026-08-11
10.0
CVSS
CRITICAL
CVE-2026-66915

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

pub. 2026-08-10
10.0
CVSS
CRITICAL
CVE-2026-65553

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

pub. 2026-08-06
10.0
CVSS
CRITICAL
CVE-2026-64633

A vulnerability allowing remote unauthenticated code execution on the agent host.

pub. 2026-08-04
10.0
CVSS
CRITICAL
CVE-2026-65880

Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.

pub. 2026-07-28
10.0
CVSS
CRITICAL
CVE-2025-71389

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.

pub. 2026-07-23
10.0
CVSS
CRITICAL
CVE-2026-47668

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.

pub. 2026-07-23
Showing 20 of 7,409 vulnerabilities
Information
ID: CWE-94
Type: Base
Vulnerabilities: 7,409
MITRE CWE ↗
← CWE Dictionary