CWE-94: Code Injection
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Yearly Trend
Top Affected Vendors
All Code Injection CVEs (1,151)
CVE-2026-27597 is a critical sandbox escape vulnerability in Enclave, a secure JavaScript sandbox for AI agent code execution. Attackers can bypass se...
Feb 25, 2026This critical vulnerability in NLTK's downloader component allows remote code execution when users download malicious zip packages. Attackers can craf...
Feb 18, 2026Crawl4AI versions before 0.8.0 contain an unauthenticated remote code execution vulnerability in the Docker API deployment. Attackers can send malicio...
Feb 12, 2026CVE-2026-25587 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can overwrite Map.prototype.has to br...
Feb 6, 2026CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use the __lookupGetter__ method t...
Feb 2, 2026SandboxJS versions before 0.8.26 have a critical sandbox escape vulnerability that allows attackers to execute arbitrary code outside the sandbox cont...
Jan 28, 2026CVE-2026-22686 is a critical sandbox escape vulnerability in enclave-vm that allows untrusted JavaScript code to execute arbitrary code in the host No...
Jan 14, 2026This critical vulnerability in Azure Container Apps allows remote attackers to execute arbitrary code via code injection. Any organization using vulne...
Dec 18, 2025CVE-2025-62521 is a critical pre-authentication remote code execution vulnerability in ChurchCRM that allows unauthenticated attackers to inject arbit...
Dec 17, 2025CVE-2025-65108 is a critical remote code execution vulnerability in md-to-pdf, a Node.js tool for converting Markdown to PDF. Attackers can execute ar...
Nov 21, 2025This critical vulnerability in VillaTheme's HAPPY helpdesk support ticket system for WordPress allows remote attackers to execute arbitrary code on af...
Nov 6, 2025This critical vulnerability in the Alone WordPress theme allows remote attackers to execute arbitrary code through improper input validation. All Word...
Oct 22, 2025Flowise versions 3.0.5 and below contain a critical remote code execution vulnerability in the CustomMCP node. Attackers can execute arbitrary JavaScr...
Sep 22, 2025CVE-2025-41243 allows attackers to modify Spring Environment properties through unsecured Spring Boot actuator endpoints in Spring Cloud Gateway Serve...
Sep 16, 2025This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code on Voltronic Power management systems via the web interf...
Aug 22, 2025This critical vulnerability in the hp Global DNS WordPress plugin allows attackers to execute arbitrary code remotely through code injection. All Word...
Aug 20, 2025This CVE describes a critical sandbox escape vulnerability in huggingface/smolagents version 1.14.0 that allows attackers to bypass execution restrict...
Jul 27, 2025CVE-2025-49302 is a critical code injection vulnerability in the Easy Stripe WordPress plugin that allows unauthenticated attackers to execute arbitra...
Jul 4, 2025This vulnerability allows non-admin users to embed scripts in reports that execute with administrator privileges on BRAIN2 servers. This affects BRAIN...
Jun 23, 2025CVE-2025-49132 is a critical remote code execution vulnerability in Pterodactyl Panel that allows unauthenticated attackers to execute arbitrary code ...
Jun 20, 2025This critical vulnerability allows remote attackers to execute arbitrary code on affected Bosch systems without authentication. It affects specific Bo...
Jun 13, 2025CVE-2025-32432 is a critical remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected servers. Thi...
Apr 25, 2025This critical vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of the DigiWidgets Image Editor W...
Apr 1, 2025This critical vulnerability in the Fresh Framework WordPress plugin allows unauthenticated attackers to execute arbitrary code on affected websites. I...
Mar 10, 2025This is a critical unauthenticated remote code execution vulnerability in Uniguest Tripleplay software. Attackers can execute arbitrary code on affect...
Mar 4, 2025This critical vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress sites using the Ark Theme Core plugin. Attackers c...
Mar 3, 2025ComfyUI-Bmad-Nodes contains a critical code injection vulnerability in three custom nodes (BuildColorRangeHSVAdvanced, FilterContour, FindContour) tha...
Dec 13, 2024CVE-2024-21574 is a critical remote code execution vulnerability in ComfyUI-Manager extension that allows attackers to execute arbitrary code on the s...
Dec 12, 2024This critical vulnerability in ABB ASPECT, NEXUS, and MATRIX series allows remote attackers to execute arbitrary code on affected systems by sending s...
Dec 5, 2024CVE-2024-50498 is a critical code injection vulnerability in the LUBUS WP Query Console WordPress plugin that allows unauthenticated remote code execu...
Oct 28, 2024This critical vulnerability in the WordPress ajax-extend plugin allows remote attackers to execute arbitrary code on affected websites. The Code Injec...
Oct 16, 2024This CVE describes a critical PHP injection vulnerability in the M4 PDF Extensions module for PrestaShop. Attackers can execute arbitrary code on affe...
Jun 24, 2024This critical vulnerability in the InstaWP Connect WordPress plugin allows attackers to upload arbitrary files and execute malicious code on affected ...
Jun 24, 2024This critical vulnerability allows unauthenticated remote code execution in Bricks Builder WordPress theme. Attackers can inject arbitrary PHP code th...
Jun 4, 2024CVE-2024-5407 is a critical PHP code injection vulnerability in RhinOS 3.0-1190 that allows remote attackers to execute arbitrary code through the sea...
May 27, 2024This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress sites running the vulnerable Canto plugin. It affects all W...
Apr 3, 2024This vulnerability in the WordPress Social Warfare plugin allows attackers to execute arbitrary code on the server via the 'swp_url' parameter. It aff...
Jan 17, 2024CVE-2023-25054 is a critical code injection vulnerability in the RSVPMaker WordPress plugin that allows remote attackers to execute arbitrary code on ...
Dec 29, 2023CVE-2023-46731 is a critical remote code execution vulnerability in XWiki Platform where improper escaping of the section URL parameter allows attacke...
Nov 6, 2023CVE-2023-41892 is a critical remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected systems. Thi...
Sep 13, 2023CVE-2023-37470 is a critical remote code execution vulnerability in Metabase that allows attackers to execute arbitrary code on the server by injectin...
Aug 4, 2023This critical vulnerability in Siemens industrial control software allows remote attackers with low privileges to execute arbitrary code with elevated...
Jun 13, 2023CVE-2023-2583 is a critical code injection vulnerability in jsreport, a JavaScript-based reporting tool. It allows attackers to execute arbitrary code...
May 8, 2023CVE-2021-27446 is a critical code injection vulnerability in Weintek cMT industrial HMI products that allows unauthenticated remote attackers to execu...
May 16, 2022CVE-2022-22947 is a critical remote code execution vulnerability in Spring Cloud Gateway when the Actuator endpoint is enabled and exposed without pro...
Mar 3, 2022CVE-2021-41269 is a critical template injection vulnerability in cron-utils Java library that allows attackers to inject arbitrary Java Expression Lan...
Nov 15, 2021CVE-2021-29475 is a critical file disclosure vulnerability in HedgeDoc (formerly CodiMD) where attackers can read arbitrary files from the filesystem ...
Apr 26, 2021CVE-2021-22205 is a critical remote code execution vulnerability in GitLab CE/EE where improper validation of image files passed to ExifTool allows at...
Apr 23, 2021This vulnerability allows unauthenticated attackers to execute arbitrary code on Eaton Intelligent Power Manager (IPM) systems by sending specially cr...
Apr 13, 2021This vulnerability in n8n allows authenticated users with workflow creation/modification permissions to escape the JavaScript Task Runner sandbox and ...
Feb 25, 2026About Code Injection (CWE-94)
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Our database tracks 1,151 CVEs classified as CWE-94, with 520 rated critical and 512 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.
External reference: View CWE-94 on MITRE CWE →
Monitor Code Injection Vulnerabilities
Get alerted when new Code Injection CVEs affect your infrastructure.
Start Monitoring Free