CWE-94: Code Injection
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Yearly Trend
Top Affected Vendors
All Code Injection CVEs (1,144)
CVE-2026-27574 allows remote code execution in OneUptime monitoring software. Any user with ProjectMember role (including anonymous users via open reg...
Feb 21, 2026Microsoft Semantic Kernel Python SDK versions before 1.39.4 contain a remote code execution vulnerability in the InMemoryVectorStore filter functional...
Feb 19, 2026This CVE describes a Server-Side Template Injection vulnerability in Datart's Freemarker template engine that allows authenticated attackers to execut...
Feb 17, 2026This vulnerability allows authenticated users with file editor permissions in CI4MS to achieve remote code execution by uploading and executing arbitr...
Feb 3, 2026This vulnerability allows authenticated attackers to execute arbitrary code on n8n workflow automation platforms, leading to full system compromise. I...
Jan 8, 2026This vulnerability allows remote code execution through improper input validation in the IF AS Shortcode WordPress plugin. Attackers can inject malici...
Dec 29, 2025CVE-2025-42880 is a critical remote code execution vulnerability in SAP Solution Manager where authenticated attackers can inject malicious code throu...
Dec 9, 2025CVE-2025-42887 is a critical code injection vulnerability in SAP Solution Manager that allows authenticated attackers to execute arbitrary code via re...
Nov 11, 2025Grafana Image Renderer versions 1.0.0 through 4.0.16 contain an arbitrary file write vulnerability in the /render/csv endpoint that allows remote code...
Oct 9, 2025This CVE describes a code injection vulnerability in Gardener Extensions for AWS, Azure, OpenStack, and GCP providers that allows administrative users...
Sep 25, 2025This critical vulnerability in SAP NetWeaver AS Java allows authenticated non-administrative users to upload arbitrary files that can be executed, lea...
Sep 9, 2025This vulnerability allows attackers to bypass MIME type validation and upload malicious PHP files disguised as Excel files to WeGIA web servers. Succe...
Sep 8, 2025CVE-2025-58159 is a critical remote code execution vulnerability in WeGIA web management software for charitable institutions. It allows attackers to ...
Aug 29, 2025CVE-2025-48169 is a critical code injection vulnerability in the WordPress Code Engine plugin that allows remote attackers to execute arbitrary code o...
Aug 20, 2025This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the vulnerable Product XML Feed Manager for WooCommerc...
Aug 14, 2025This critical vulnerability in SAP S/4HANA allows authenticated users to inject arbitrary ABAP code via RFC-exposed function modules, bypassing author...
Aug 12, 2025CVE-2025-42950 is a critical code injection vulnerability in SAP Landscape Transformation (SLT) that allows authenticated users to execute arbitrary A...
Aug 12, 2025This CVE describes a critical code injection vulnerability in the MetalpriceAPI WordPress plugin that allows remote code execution. Attackers can inje...
Jun 9, 2025This CVE describes a critical code injection vulnerability in WilderForge GitHub Actions workflows where user-controlled variables like ${{ github.eve...
Jun 9, 2025This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of the PDF 2 Post WordPress plugin. Attack...
Apr 17, 2025CVE-2025-31330 is a critical code injection vulnerability in SAP Landscape Transformation (SLT) that allows authenticated users to execute arbitrary A...
Apr 8, 2025This critical vulnerability in SAP S/4HANA allows authenticated users to inject arbitrary ABAP code via RFC function modules, bypassing authorization ...
Apr 8, 2025This CVE describes a critical remote code execution vulnerability in pgAdmin 4 where attacker-controlled input is passed to Python's eval() function. ...
Apr 3, 2025This critical vulnerability in RomethemeKit For Elementor WordPress plugin allows authenticated attackers to execute arbitrary code through command in...
Apr 1, 2025This CVE describes a critical remote code execution vulnerability in the Visual Text Editor WordPress plugin. Attackers can inject malicious code thro...
Mar 26, 2025This vulnerability allows remote attackers to execute arbitrary commands on ToDesktop build servers by exploiting postinstall scripts in package.json ...
Mar 1, 2025This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the vulnerable Post/Page Copying Tool plugin. Attacker...
Feb 4, 2025CVE-2025-22133 is a critical file upload vulnerability in WeGIA web management software that allows unauthenticated attackers to upload malicious .pha...
Jan 7, 2025This critical vulnerability allows an attacker with access to a VSPC management agent machine to execute arbitrary code on the VSPC server, potentiall...
Dec 12, 2024This vulnerability allows authenticated attackers with contributor-level access or higher to execute arbitrary code on WordPress servers through the W...
Nov 28, 2024This critical vulnerability allows low-privileged users to upload arbitrary files to VSPC servers, leading to remote code execution. Attackers can gai...
Sep 7, 2024This critical vulnerability allows administrators with restricted permissions to execute arbitrary code via the Ping script in Zabbix monitoring syste...
Aug 12, 2024This CVE describes a remote code execution vulnerability in JupyterLab extension template's GitHub Actions workflow. Attackers can execute arbitrary c...
Jul 16, 2024This vulnerability allows authenticated users with access to Thruk's reporting functionality to execute arbitrary commands on the server via URL param...
Jul 15, 2024CVE-2024-39932 is an argument injection vulnerability in Gogs that allows attackers to execute arbitrary commands on the server during change preview ...
Jul 4, 2024This vulnerability allows authenticated attackers to execute arbitrary PHP code on WordPress sites running vulnerable versions of the WishList Member ...
Jun 24, 2024This vulnerability allows remote code execution in the WordPress Customify Site Library plugin. Attackers can inject and execute arbitrary code on aff...
May 17, 2024This vulnerability allows authenticated users with Subscriber-level permissions in WordPress to inject and execute arbitrary PHP code through the Main...
May 17, 2024This CVE describes a critical code injection vulnerability in the Cwicly Builder WordPress plugin that allows remote code execution. Attackers can inj...
Apr 3, 2024This vulnerability allows authenticated attackers to execute arbitrary code on WordPress sites using Oxygen Builder. It affects all versions up to 4.9...
Apr 3, 2024This CVE describes a Jinja2 template injection vulnerability in JumpServer's Ansible component that allows authenticated attackers to execute arbitrar...
Mar 29, 2024This vulnerability allows remote code execution (RCE) in the Astra Pro WordPress plugin. Attackers can inject and execute arbitrary code on affected w...
Dec 29, 2023This vulnerability allows remote code execution in the WP EXtra WordPress plugin through improper .htaccess file modification. Attackers can inject ma...
Dec 29, 2023This vulnerability in XWiki Platform allows any user who can edit a wiki page to gain programming rights through missing escaping in administration in...
Dec 15, 2023This vulnerability in XWiki Platform allows authenticated users to inject malicious XWiki syntax containing script macros through the search administr...
Dec 15, 2023This vulnerability in XWiki Platform allows authenticated users with edit rights to execute arbitrary Groovy code on the server by exploiting improper...
Nov 7, 2023This vulnerability allows any user with view access to the Invitation.WebHome page in XWiki Platform to execute arbitrary script macros, including Gro...
Aug 17, 2023CVE-2023-34251 is a server-side template injection vulnerability in Grav CMS that allows authenticated users with page editing privileges to execute a...
Jun 14, 2023CVE-2022-25759 is a critical remote code injection vulnerability in convert-svg-core package versions before 0.6.2. Attackers can execute arbitrary co...
Jul 22, 2022CVE-2022-24664 is a critical remote code execution vulnerability in PHP Everywhere WordPress plugin. It allows any user with post editing permissions ...
Feb 16, 2022About Code Injection (CWE-94)
The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.
Our database tracks 1,144 CVEs classified as CWE-94, with 517 rated critical and 508 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.
External reference: View CWE-94 on MITRE CWE →
Monitor Code Injection Vulnerabilities
Get alerted when new Code Injection CVEs affect your infrastructure.
Start Monitoring Free