CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,142
Total CVEs
517
Critical
506
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Craftcms 7
10 Ivanti 7

All Code Injection CVEs (1,142)

CVE-2026-27597
10.0

CVE-2026-27597 is a critical sandbox escape vulnerability in Enclave, a secure JavaScript sandbox for AI agent code execution. Attackers can bypass se...

Feb 25, 2026
CVE-2025-14009
10.0

This critical vulnerability in NLTK's downloader component allows remote code execution when users download malicious zip packages. Attackers can craf...

Feb 18, 2026
CVE-2026-26216
10.0

Crawl4AI versions before 0.8.0 contain an unauthenticated remote code execution vulnerability in the Docker API deployment. Attackers can send malicio...

Feb 12, 2026
CVE-2026-25587
10.0

CVE-2026-25587 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can overwrite Map.prototype.has to br...

Feb 6, 2026
CVE-2026-25142
10.0

CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use the __lookupGetter__ method t...

Feb 2, 2026
CVE-2026-23830
10.0

SandboxJS versions before 0.8.26 have a critical sandbox escape vulnerability that allows attackers to execute arbitrary code outside the sandbox cont...

Jan 28, 2026
CVE-2026-22686
10.0

CVE-2026-22686 is a critical sandbox escape vulnerability in enclave-vm that allows untrusted JavaScript code to execute arbitrary code in the host No...

Jan 14, 2026
CVE-2025-65037
10.0

This critical vulnerability in Azure Container Apps allows remote attackers to execute arbitrary code via code injection. Any organization using vulne...

Dec 18, 2025
CVE-2025-62521
10.0

CVE-2025-62521 is a critical pre-authentication remote code execution vulnerability in ChurchCRM that allows unauthenticated attackers to inject arbit...

Dec 17, 2025
CVE-2025-65108
10.0

CVE-2025-65108 is a critical remote code execution vulnerability in md-to-pdf, a Node.js tool for converting Markdown to PDF. Attackers can execute ar...

Nov 21, 2025
CVE-2025-49372
10.0

This critical vulnerability in VillaTheme's HAPPY helpdesk support ticket system for WordPress allows remote attackers to execute arbitrary code on af...

Nov 6, 2025
CVE-2025-60206
10.0

This critical vulnerability in the Alone WordPress theme allows remote attackers to execute arbitrary code through improper input validation. All Word...

Oct 22, 2025
CVE-2025-59528
EPSS 84.1% 10.0

Flowise versions 3.0.5 and below contain a critical remote code execution vulnerability in the CustomMCP node. Attackers can execute arbitrary JavaScr...

Sep 22, 2025
CVE-2025-41243
10.0

CVE-2025-41243 allows attackers to modify Spring Environment properties through unsecured Spring Boot actuator endpoints in Spring Cloud Gateway Serve...

Sep 16, 2025
CVE-2022-31491
10.0

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code on Voltronic Power management systems via the web interf...

Aug 22, 2025
CVE-2025-53577
10.0

This critical vulnerability in the hp Global DNS WordPress plugin allows attackers to execute arbitrary code remotely through code injection. All Word...

Aug 20, 2025
CVE-2025-5120
10.0

This CVE describes a critical sandbox escape vulnerability in huggingface/smolagents version 1.14.0 that allows attackers to bypass execution restrict...

Jul 27, 2025
CVE-2025-49302
10.0

CVE-2025-49302 is a critical code injection vulnerability in the Easy Stripe WordPress plugin that allows unauthenticated attackers to execute arbitra...

Jul 4, 2025
CVE-2025-6512
10.0

This vulnerability allows non-admin users to embed scripts in reports that execute with administrator privileges on BRAIN2 servers. This affects BRAIN...

Jun 23, 2025
CVE-2025-49132
EPSS 35.4% 10.0

CVE-2025-49132 is a critical remote code execution vulnerability in Pterodactyl Panel that allows unauthenticated attackers to execute arbitrary code ...

Jun 20, 2025
CVE-2025-29902
10.0

This critical vulnerability allows remote attackers to execute arbitrary code on affected Bosch systems without authentication. It affects specific Bo...

Jun 13, 2025
CVE-2025-32432
EPSS 77.4% 10.0

CVE-2025-32432 is a critical remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected servers. Thi...

Apr 25, 2025
CVE-2025-30580
10.0

This critical vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of the DigiWidgets Image Editor W...

Apr 1, 2025
CVE-2025-26936
10.0

This critical vulnerability in the Fresh Framework WordPress plugin allows unauthenticated attackers to execute arbitrary code on affected websites. I...

Mar 10, 2025
CVE-2024-50704
10.0

This is a critical unauthenticated remote code execution vulnerability in Uniguest Tripleplay software. Attackers can execute arbitrary code on affect...

Mar 4, 2025
CVE-2025-26970
10.0

This critical vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress sites using the Ark Theme Core plugin. Attackers c...

Mar 3, 2025
CVE-2024-21576
10.0

ComfyUI-Bmad-Nodes contains a critical code injection vulnerability in three custom nodes (BuildColorRangeHSVAdvanced, FilterContour, FindContour) tha...

Dec 13, 2024
CVE-2024-21574
10.0

CVE-2024-21574 is a critical remote code execution vulnerability in ComfyUI-Manager extension that allows attackers to execute arbitrary code on the s...

Dec 12, 2024
CVE-2024-48839
10.0

This critical vulnerability in ABB ASPECT, NEXUS, and MATRIX series allows remote attackers to execute arbitrary code on affected systems by sending s...

Dec 5, 2024
CVE-2024-50498
10.0

CVE-2024-50498 is a critical code injection vulnerability in the LUBUS WP Query Console WordPress plugin that allows unauthenticated remote code execu...

Oct 28, 2024
CVE-2024-49254
10.0

This critical vulnerability in the WordPress ajax-extend plugin allows remote attackers to execute arbitrary code on affected websites. The Code Injec...

Oct 16, 2024
CVE-2023-50029
10.0

This CVE describes a critical PHP injection vulnerability in the M4 PDF Extensions module for PrestaShop. Attackers can execute arbitrary code on affe...

Jun 24, 2024
CVE-2024-37228
10.0

This critical vulnerability in the InstaWP Connect WordPress plugin allows attackers to upload arbitrary files and execute malicious code on affected ...

Jun 24, 2024
CVE-2024-25600
10.0

This critical vulnerability allows unauthenticated remote code execution in Bricks Builder WordPress theme. Attackers can inject arbitrary PHP code th...

Jun 4, 2024
CVE-2024-5407
10.0

CVE-2024-5407 is a critical PHP code injection vulnerability in RhinOS 3.0-1190 that allows remote attackers to execute arbitrary code through the sea...

May 27, 2024
CVE-2024-25096
10.0

This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress sites running the vulnerable Canto plugin. It affects all W...

Apr 3, 2024
CVE-2021-4434
10.0

This vulnerability in the WordPress Social Warfare plugin allows attackers to execute arbitrary code on the server via the 'swp_url' parameter. It aff...

Jan 17, 2024
CVE-2023-25054
10.0

CVE-2023-25054 is a critical code injection vulnerability in the RSVPMaker WordPress plugin that allows remote attackers to execute arbitrary code on ...

Dec 29, 2023
CVE-2023-46731
10.0

CVE-2023-46731 is a critical remote code execution vulnerability in XWiki Platform where improper escaping of the section URL parameter allows attacke...

Nov 6, 2023
CVE-2023-41892
10.0

CVE-2023-41892 is a critical remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected systems. Thi...

Sep 13, 2023
CVE-2023-37470
10.0

CVE-2023-37470 is a critical remote code execution vulnerability in Metabase that allows attackers to execute arbitrary code on the server by injectin...

Aug 4, 2023
CVE-2023-25910
10.0

This critical vulnerability in Siemens industrial control software allows remote attackers with low privileges to execute arbitrary code with elevated...

Jun 13, 2023
CVE-2023-2583
10.0

CVE-2023-2583 is a critical code injection vulnerability in jsreport, a JavaScript-based reporting tool. It allows attackers to execute arbitrary code...

May 8, 2023
CVE-2021-27446
10.0

CVE-2021-27446 is a critical code injection vulnerability in Weintek cMT industrial HMI products that allows unauthenticated remote attackers to execu...

May 16, 2022
CVE-2022-22947
10.0

CVE-2022-22947 is a critical remote code execution vulnerability in Spring Cloud Gateway when the Actuator endpoint is enabled and exposed without pro...

Mar 3, 2022
CVE-2021-41269
10.0

CVE-2021-41269 is a critical template injection vulnerability in cron-utils Java library that allows attackers to inject arbitrary Java Expression Lan...

Nov 15, 2021
CVE-2021-29475
10.0

CVE-2021-29475 is a critical file disclosure vulnerability in HedgeDoc (formerly CodiMD) where attackers can read arbitrary files from the filesystem ...

Apr 26, 2021
CVE-2021-22205
10.0

CVE-2021-22205 is a critical remote code execution vulnerability in GitLab CE/EE where improper validation of image files passed to ExifTool allows at...

Apr 23, 2021
CVE-2021-23281
10.0

This vulnerability allows unauthenticated attackers to execute arbitrary code on Eaton Intelligent Power Manager (IPM) systems by sending specially cr...

Apr 13, 2021
CVE-2026-27495
9.9

This vulnerability in n8n allows authenticated users with workflow creation/modification permissions to escape the JavaScript Task Runner sandbox and ...

Feb 25, 2026

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,142 CVEs classified as CWE-94, with 517 rated critical and 506 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free