CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,169
Total CVEs
531
Critical
519
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 11
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Google 7
9 Craftcms 7
10 Moodle 7

All Code Injection CVEs (1,169)

CVE-2023-24709
7.5

This vulnerability in Paradox Security Systems IPR512 allows attackers to cause denial of service by exploiting injection vulnerabilities in login.htm...

Mar 21, 2023
CVE-2023-24576
7.5

CVE-2023-24576 is an unauthenticated remote code execution vulnerability in EMC NetWorker's nsrexecd service. This allows attackers to execute arbitra...

Feb 3, 2023
CVE-2022-24429
7.5

CVE-2022-24429 is an arbitrary code injection vulnerability in convert-svg-core that allows attackers to read arbitrary files from the file system whe...

Jun 10, 2022
CVE-2021-37097
7.5

This CVE describes a code injection vulnerability in Huawei smartphones running HarmonyOS. Successful exploitation could allow an attacker to execute ...

Dec 8, 2021
CVE-2021-32831
7.5

CVE-2021-32831 is a code injection vulnerability in the Total.js framework for Node.js. When the utils.set function is called with user-controlled val...

Aug 30, 2021
CVE-2021-22336
7.5

This CVE describes an Improper Control of Generation of Code vulnerability in Huawei smartphones that allows attackers to execute arbitrary code on ro...

Jun 3, 2021
CVE-2020-28367
7.5

This CVE allows arbitrary code execution during build time when using Go's cgo feature with malicious gcc flags specified in #cgo directives. Attacker...

Nov 18, 2020
CVE-2024-42911
7.4

This vulnerability allows remote attackers to execute arbitrary code on ECOVACS Deebot T20 OMNI and T20e OMNI robot vacuums via WiFi. Attackers could ...

Jan 14, 2025
CVE-2025-33042
7.3

This vulnerability allows remote code execution when Apache Avro Java SDK processes untrusted Avro schemas. Attackers can inject malicious code that g...

Feb 13, 2026
CVE-2024-11976
7.3

This vulnerability in the BuddyPress WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes. This affects all WordPress sit...

Jan 23, 2026
CVE-2025-12120
7.3

Lite XL versions 2.1.8 and earlier automatically execute Lua code from .lite_project.lua files when opening project directories without user confirmat...

Nov 20, 2025
CVE-2025-7366
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes in the REHub theme. Attackers can inject malicious short...

Sep 6, 2025
CVE-2025-6744
7.3

The Woodmart WordPress theme allows unauthenticated attackers to execute arbitrary shortcodes due to insufficient input validation in the woodmart_get...

Jul 8, 2025
CVE-2024-13793
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes in the Wolmart theme. Attackers can inject malicious sho...

May 8, 2025
CVE-2025-2802
7.3

The LayoutBoxx WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerability ...

May 6, 2025
CVE-2024-13738
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes in the Motors WordPress theme. Attackers can potentially...

May 3, 2025
CVE-2025-2801
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the Create custom forms for WordPress with a sma...

Apr 26, 2025
CVE-2025-32596
7.3

This CVE describes a code injection vulnerability in the Real Estate Manager WordPress plugin that allows attackers to execute arbitrary code on affec...

Apr 17, 2025
CVE-2025-2805
7.3

The ORDER POST WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerability ...

Apr 10, 2025
CVE-2025-1119
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the Simply Schedule Appointments Booking Plugin....

Mar 13, 2025
CVE-2025-2169
7.3

The WPCS WordPress Currency Switcher Professional plugin up to version 1.2.0.4 allows unauthenticated attackers to execute arbitrary WordPress shortco...

Mar 11, 2025
CVE-2025-1510
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the Custom Post Type Date Archives plugin. Attac...

Feb 22, 2025
CVE-2025-1509
7.3

The Show Me The Cookies WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This affec...

Feb 22, 2025
CVE-2025-25944
7.3

A buffer overflow vulnerability in Bento4 v1.6.0-641 allows local attackers to execute arbitrary code by crafting a malicious MP4 file and processing ...

Feb 19, 2025
CVE-2024-13797
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes in the PressMart theme. Attackers can potentially inject...

Feb 18, 2025
CVE-2024-13346
EPSS 35.4% 7.3

This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes in the Avada WordPress theme, potentially leading to remote code e...

Feb 13, 2025
CVE-2024-13345
7.3

The Avada Builder WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerabili...

Feb 13, 2025
CVE-2024-13487
7.3

The CURCY WooCommerce plugin allows unauthenticated attackers to execute arbitrary WordPress shortcodes via the get_products_price() function. This vu...

Feb 6, 2025
CVE-2024-13472
7.3

The WooCommerce Product Table Lite plugin for WordPress allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validat...

Jan 31, 2025
CVE-2024-13453
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the PirateForms contact form plugin. Attackers c...

Jan 30, 2025
CVE-2024-13495
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the GamiPress plugin's AJAX function. Attackers ...

Jan 22, 2025
CVE-2024-13499
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the GamiPress plugin. Attackers can potentially ...

Jan 22, 2025
CVE-2024-11733
7.3

The WordPress Popular Posts plugin up to version 7.1.0 allows unauthenticated attackers to execute arbitrary WordPress shortcodes due to insufficient ...

Jan 3, 2025
CVE-2024-11977
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the kk Star Ratings plugin. Attackers can potent...

Dec 21, 2024
CVE-2024-10959
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes via the woot_get_smth AJAX action in the Active Products...

Dec 10, 2024
CVE-2024-37860
7.3

A buffer overflow vulnerability in ROS2 navigation2 allows local attackers to execute arbitrary code by providing a malicious .yaml file to the nav2_a...

Dec 5, 2024
CVE-2024-10952
7.3

The Authors List WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes via a vulnerable AJAX endpoint. This vulnerability ...

Dec 4, 2024
CVE-2024-11034
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the 'fire_contact_form' AJAX action in the Reque...

Nov 23, 2024
CVE-2024-11036
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes via the gamipress_get_user_earnings AJAX action. All Wor...

Nov 19, 2024
CVE-2024-9839
7.3

The Uix Slideshow WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerabili...

Nov 16, 2024
CVE-2024-21541
7.3

This vulnerability allows arbitrary code execution in applications using vulnerable versions of the dom-iterator package. Attackers can inject malicio...

Nov 13, 2024
CVE-2024-10958
7.3

The WP Photo Album Plus WordPress plugin contains an arbitrary shortcode execution vulnerability that allows unauthenticated attackers to execute arbi...

Nov 10, 2024
CVE-2024-10640
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the FOX Currency Switcher Professional plugin. A...

Nov 9, 2024
CVE-2024-10261
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes in the Paid Membership Subscriptions plugin. Attackers c...

Nov 9, 2024
CVE-2024-10263
7.3

The Tickera WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerability aff...

Nov 5, 2024
CVE-2024-9846
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the Enable Shortcodes plugin. Attackers can pote...

Oct 30, 2024
CVE-2024-50450
7.3

This vulnerability allows attackers to inject and execute arbitrary code on WordPress sites using the Meta Data and Taxonomies Filter (MDTF) plugin. I...

Oct 28, 2024
CVE-2024-9772
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the Uix Shortcodes plugin. All WordPress sites u...

Oct 26, 2024
CVE-2024-8481
7.3

The Special Text Boxes WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes through comments. This vulnerability affects ...

Sep 25, 2024
CVE-2024-8623
7.3

The MDTF WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This affects all WordPres...

Sep 24, 2024

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,169 CVEs classified as CWE-94, with 531 rated critical and 519 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free