CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,144
Total CVEs
517
Critical
508
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Fedoraproject 10
5 Seacms 10
6 Xwiki 9
7 Apple 9
8 Google 7
9 Craftcms 7
10 Ivanti 7

All Code Injection CVEs (1,144)

CVE-2026-27574
9.9

CVE-2026-27574 allows remote code execution in OneUptime monitoring software. Any user with ProjectMember role (including anonymous users via open reg...

Feb 21, 2026
CVE-2026-26030
9.9

Microsoft Semantic Kernel Python SDK versions before 1.39.4 contain a remote code execution vulnerability in the InMemoryVectorStore filter functional...

Feb 19, 2026
CVE-2025-70830
9.9

This CVE describes a Server-Side Template Injection vulnerability in Datart's Freemarker template engine that allows authenticated attackers to execut...

Feb 17, 2026
CVE-2026-25510
9.9

This vulnerability allows authenticated users with file editor permissions in CI4MS to achieve remote code execution by uploading and executing arbitr...

Feb 3, 2026
CVE-2026-21877
EPSS 14.6% 9.9

This vulnerability allows authenticated attackers to execute arbitrary code on n8n workflow automation platforms, leading to full system compromise. I...

Jan 8, 2026
CVE-2025-68897
9.9

This vulnerability allows remote code execution through improper input validation in the IF AS Shortcode WordPress plugin. Attackers can inject malici...

Dec 29, 2025
CVE-2025-42880
9.9

CVE-2025-42880 is a critical remote code execution vulnerability in SAP Solution Manager where authenticated attackers can inject malicious code throu...

Dec 9, 2025
CVE-2025-42887
9.9

CVE-2025-42887 is a critical code injection vulnerability in SAP Solution Manager that allows authenticated attackers to execute arbitrary code via re...

Nov 11, 2025
CVE-2025-11539
9.9

Grafana Image Renderer versions 1.0.0 through 4.0.16 contain an arbitrary file write vulnerability in the /render/csv endpoint that allows remote code...

Oct 9, 2025
CVE-2025-59823
9.9

This CVE describes a code injection vulnerability in Gardener Extensions for AWS, Azure, OpenStack, and GCP providers that allows administrative users...

Sep 25, 2025
CVE-2025-42922
9.9

This critical vulnerability in SAP NetWeaver AS Java allows authenticated non-administrative users to upload arbitrary files that can be executed, lea...

Sep 9, 2025
CVE-2025-58745
9.9

This vulnerability allows attackers to bypass MIME type validation and upload malicious PHP files disguised as Excel files to WeGIA web servers. Succe...

Sep 8, 2025
CVE-2025-58159
9.9

CVE-2025-58159 is a critical remote code execution vulnerability in WeGIA web management software for charitable institutions. It allows attackers to ...

Aug 29, 2025
CVE-2025-48169
9.9

CVE-2025-48169 is a critical code injection vulnerability in the WordPress Code Engine plugin that allows remote attackers to execute arbitrary code o...

Aug 20, 2025
CVE-2025-49887
9.9

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the vulnerable Product XML Feed Manager for WooCommerc...

Aug 14, 2025
CVE-2025-42957
9.9

This critical vulnerability in SAP S/4HANA allows authenticated users to inject arbitrary ABAP code via RFC-exposed function modules, bypassing author...

Aug 12, 2025
CVE-2025-42950
9.9

CVE-2025-42950 is a critical code injection vulnerability in SAP Landscape Transformation (SLT) that allows authenticated users to execute arbitrary A...

Aug 12, 2025
CVE-2025-48140
9.9

This CVE describes a critical code injection vulnerability in the MetalpriceAPI WordPress plugin that allows remote code execution. Attackers can inje...

Jun 9, 2025
CVE-2025-49013
9.9

This CVE describes a critical code injection vulnerability in WilderForge GitHub Actions workflows where user-controlled variables like ${{ github.eve...

Jun 9, 2025
CVE-2025-32583
9.9

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of the PDF 2 Post WordPress plugin. Attack...

Apr 17, 2025
CVE-2025-31330
9.9

CVE-2025-31330 is a critical code injection vulnerability in SAP Landscape Transformation (SLT) that allows authenticated users to execute arbitrary A...

Apr 8, 2025
CVE-2025-27429
9.9

This critical vulnerability in SAP S/4HANA allows authenticated users to inject arbitrary ABAP code via RFC function modules, bypassing authorization ...

Apr 8, 2025
CVE-2025-2945
EPSS 77.9% 9.9

This CVE describes a critical remote code execution vulnerability in pgAdmin 4 where attacker-controlled input is passed to Python's eval() function. ...

Apr 3, 2025
CVE-2025-30911
9.9

This critical vulnerability in RomethemeKit For Elementor WordPress plugin allows authenticated attackers to execute arbitrary code through command in...

Apr 1, 2025
CVE-2025-28893
9.9

This CVE describes a critical remote code execution vulnerability in the Visual Text Editor WordPress plugin. Attackers can inject malicious code thro...

Mar 26, 2025
CVE-2025-27554
9.9

This vulnerability allows remote attackers to execute arbitrary commands on ToDesktop build servers by exploiting postinstall scripts in package.json ...

Mar 1, 2025
CVE-2025-24677
9.9

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the vulnerable Post/Page Copying Tool plugin. Attacker...

Feb 4, 2025
CVE-2025-22133
9.9

CVE-2025-22133 is a critical file upload vulnerability in WeGIA web management software that allows unauthenticated attackers to upload malicious .pha...

Jan 7, 2025
CVE-2024-42448
9.9

This critical vulnerability allows an attacker with access to a VSPC management agent machine to execute arbitrary code on the VSPC server, potentiall...

Dec 12, 2024
CVE-2024-8672
9.9

This vulnerability allows authenticated attackers with contributor-level access or higher to execute arbitrary code on WordPress servers through the W...

Nov 28, 2024
CVE-2024-39714
9.9

This critical vulnerability allows low-privileged users to upload arbitrary files to VSPC servers, leading to remote code execution. Attackers can gai...

Sep 7, 2024
CVE-2024-22116
9.9

This critical vulnerability allows administrators with restricted permissions to execute arbitrary code via the Ping script in Zabbix monitoring syste...

Aug 12, 2024
CVE-2024-39700
9.9

This CVE describes a remote code execution vulnerability in JupyterLab extension template's GitHub Actions workflow. Attackers can execute arbitrary c...

Jul 16, 2024
CVE-2024-39915
9.9

This vulnerability allows authenticated users with access to Thruk's reporting functionality to execute arbitrary commands on the server via URL param...

Jul 15, 2024
CVE-2024-39932
9.9

CVE-2024-39932 is an argument injection vulnerability in Gogs that allows attackers to execute arbitrary commands on the server during change preview ...

Jul 4, 2024
CVE-2024-37109
9.9

This vulnerability allows authenticated attackers to execute arbitrary PHP code on WordPress sites running vulnerable versions of the WishList Member ...

Jun 24, 2024
CVE-2024-33644
9.9

This vulnerability allows remote code execution in the WordPress Customify Site Library plugin. Attackers can inject and execute arbitrary code on aff...

May 17, 2024
CVE-2023-23645
9.9

This vulnerability allows authenticated users with Subscriber-level permissions in WordPress to inject and execute arbitrary PHP code through the Main...

May 17, 2024
CVE-2024-24707
9.9

This CVE describes a critical code injection vulnerability in the Cwicly Builder WordPress plugin that allows remote code execution. Attackers can inj...

Apr 3, 2024
CVE-2024-31380
9.9

This vulnerability allows authenticated attackers to execute arbitrary code on WordPress sites using Oxygen Builder. It affects all versions up to 4.9...

Apr 3, 2024
CVE-2024-29202
9.9

This CVE describes a Jinja2 template injection vulnerability in JumpServer's Ansible component that allows authenticated attackers to execute arbitrar...

Mar 29, 2024
CVE-2023-49830
9.9

This vulnerability allows remote code execution (RCE) in the Astra Pro WordPress plugin. Attackers can inject and execute arbitrary code on affected w...

Dec 29, 2023
CVE-2023-46623
9.9

This vulnerability allows remote code execution in the WP EXtra WordPress plugin through improper .htaccess file modification. Attackers can inject ma...

Dec 29, 2023
CVE-2023-50723
9.9

This vulnerability in XWiki Platform allows any user who can edit a wiki page to gain programming rights through missing escaping in administration in...

Dec 15, 2023
CVE-2023-50721
9.9

This vulnerability in XWiki Platform allows authenticated users to inject malicious XWiki syntax containing script macros through the search administr...

Dec 15, 2023
CVE-2023-46243
9.9

This vulnerability in XWiki Platform allows authenticated users with edit rights to execute arbitrary Groovy code on the server by exploiting improper...

Nov 7, 2023
CVE-2023-37914
9.9

This vulnerability allows any user with view access to the Invitation.WebHome page in XWiki Platform to execute arbitrary script macros, including Gro...

Aug 17, 2023
CVE-2023-34251
9.9

CVE-2023-34251 is a server-side template injection vulnerability in Grav CMS that allows authenticated users with page editing privileges to execute a...

Jun 14, 2023
CVE-2022-25759
9.9

CVE-2022-25759 is a critical remote code injection vulnerability in convert-svg-core package versions before 0.6.2. Attackers can execute arbitrary co...

Jul 22, 2022
CVE-2022-24664
9.9

CVE-2022-24664 is a critical remote code execution vulnerability in PHP Everywhere WordPress plugin. It allows any user with post editing permissions ...

Feb 16, 2022

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,144 CVEs classified as CWE-94, with 517 rated critical and 508 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free