CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,183
Total CVEs
539
Critical
525
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 11
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Ivanti 8
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,183)

CVE-2024-9839
7.3

The Uix Slideshow WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerabili...

Nov 16, 2024
CVE-2024-21541
7.3

This vulnerability allows arbitrary code execution in applications using vulnerable versions of the dom-iterator package. Attackers can inject malicio...

Nov 13, 2024
CVE-2024-10958
7.3

The WP Photo Album Plus WordPress plugin contains an arbitrary shortcode execution vulnerability that allows unauthenticated attackers to execute arbi...

Nov 10, 2024
CVE-2024-10640
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the FOX Currency Switcher Professional plugin. A...

Nov 9, 2024
CVE-2024-10261
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes in the Paid Membership Subscriptions plugin. Attackers c...

Nov 9, 2024
CVE-2024-10263
7.3

The Tickera WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This vulnerability aff...

Nov 5, 2024
CVE-2024-9846
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the Enable Shortcodes plugin. Attackers can pote...

Oct 30, 2024
CVE-2024-50450
7.3

This vulnerability allows attackers to inject and execute arbitrary code on WordPress sites using the Meta Data and Taxonomies Filter (MDTF) plugin. I...

Oct 28, 2024
CVE-2024-9772
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the Uix Shortcodes plugin. All WordPress sites u...

Oct 26, 2024
CVE-2024-8481
7.3

The Special Text Boxes WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes through comments. This vulnerability affects ...

Sep 25, 2024
CVE-2024-8623
7.3

The MDTF WordPress plugin allows unauthenticated attackers to execute arbitrary shortcodes due to improper input validation. This affects all WordPres...

Sep 24, 2024
CVE-2024-8479
7.3

The Simple Spoiler WordPress plugin versions 1.2 to 1.3 allow unauthenticated attackers to execute arbitrary shortcodes via comments. This vulnerabili...

Sep 14, 2024
CVE-2024-8271
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the FOX – Currency Switcher Professional for W...

Sep 14, 2024
CVE-2024-45390
7.3

CVE-2024-45390 is a code injection vulnerability in the @blakeembrey/template JavaScript library that allows attackers to execute arbitrary code when ...

Sep 3, 2024
CVE-2023-36014
7.3

This vulnerability in Microsoft Edge (Chromium-based) allows remote attackers to execute arbitrary code on affected systems by tricking users into vis...

Nov 10, 2023
CVE-2023-36592
7.3

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted ...

Oct 10, 2023
CVE-2017-20099
7.3

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the vulnerable Analytics Stats Counter Statistics Plug...

Jun 27, 2022
CVE-2026-3352
7.2

The Easy PHP Settings WordPress plugin allows authenticated attackers with Administrator privileges to inject arbitrary PHP code into wp-config.php vi...

Mar 7, 2026
CVE-2026-25887
7.2

Chartbrew versions before 4.8.1 contain a remote code execution vulnerability in MongoDB dataset queries. Attackers can execute arbitrary code on the ...

Mar 6, 2026
CVE-2026-26045
7.2

This vulnerability in Moodle's backup restore functionality allows authenticated privileged users to upload specially crafted backup files that bypass...

Feb 21, 2026
CVE-2026-2296
7.2

This vulnerability allows authenticated attackers with Shop Manager or higher WordPress roles to execute arbitrary PHP code on the server. The flaw ex...

Feb 18, 2026
CVE-2025-14541
7.2

The Lucky Wheel Giveaway WordPress plugin contains a remote code execution vulnerability in all versions up to 1.0.22. Authenticated attackers with Ad...

Feb 11, 2026
CVE-2025-70073
7.2

A remote code execution vulnerability in ChestnutCMS v1.5.8 and earlier allows attackers to execute arbitrary code through the template creation funct...

Feb 5, 2026
CVE-2021-47778
7.2

CVE-2021-47778 is a PHP code injection vulnerability in GetSimple CMS My SMTP Contact Plugin 1.1.2 that allows authenticated administrators to execute...

Jan 21, 2026
CVE-2026-23498
7.2

This CVE describes a code injection vulnerability in Shopware's map() function where PHP Closures can bypass allow-list validation. It affects Shopwar...

Jan 14, 2026
CVE-2025-68619
7.2

Signal K Server versions before 2.19.0 allow authenticated administrators to install npm packages from arbitrary sources via the appstore interface. T...

Jan 1, 2026
CVE-2025-14509
7.2

This vulnerability allows authenticated WordPress administrators to execute arbitrary PHP code on servers running the Lucky Wheel for WooCommerce plug...

Dec 30, 2025
CVE-2025-13592
7.2

The Advanced Ads WordPress plugin up to version 2.0.14 contains a remote code execution vulnerability via the 'change-ad__content' shortcode parameter...

Dec 29, 2025
CVE-2025-64676
7.2

This vulnerability in Microsoft Purview allows authenticated attackers to execute arbitrary code remotely by exploiting improper input validation in p...

Dec 18, 2025
CVE-2023-53883
7.2

CVE-2023-53883 is a remote code execution vulnerability in Webedition CMS v2.9.8.8 that allows authenticated attackers to execute arbitrary system com...

Dec 15, 2025
CVE-2024-58284
7.2

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability where administrative users can inject malicious PHP code through meta...

Dec 10, 2025
CVE-2025-64050
7.2

A Remote Code Execution vulnerability in REDAXO CMS 5.20.0 allows authenticated administrators to inject PHP code into templates, which executes when ...

Nov 25, 2025
CVE-2025-62429
7.2

This vulnerability allows remote code execution in ClipBucket v5 video sharing platform. Attackers can inject malicious PHP code through the 'type' pa...

Oct 20, 2025
CVE-2025-9517
7.2

The atec Debug plugin for WordPress has a remote code execution vulnerability that allows authenticated attackers with Administrator privileges to exe...

Sep 4, 2025
CVE-2025-9519
7.2

The Easy Timer WordPress plugin allows authenticated attackers with Editor-level permissions or higher to execute arbitrary code on the server through...

Sep 4, 2025
CVE-2025-54593
7.2

This vulnerability allows authenticated administrator users in FreshRSS versions 1.26.1 and below to execute arbitrary code on the server by modifying...

Aug 1, 2025
CVE-2024-58258
7.2

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in SugarCRM's API module that allows attackers to make unauthorized requests fro...

Jul 13, 2025
CVE-2025-52718
7.2

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites using the Alone theme. Attackers can inject malicious code tha...

Jul 4, 2025
CVE-2025-25021
7.2

This vulnerability in IBM QRadar Suite and Cloud Pak for Security allows privileged users to execute arbitrary code when creating case management scri...

Jun 3, 2025
CVE-2025-48390
7.2

FreeScout versions before 1.8.178 contain a code injection vulnerability in the php_path parameter. Administrators can exploit this to execute arbitra...

May 29, 2025
CVE-2024-13928
7.2

SQL injection vulnerabilities in ASPECT software allow attackers to execute arbitrary SQL commands when session administrator credentials are compromi...

May 22, 2025
CVE-2025-4428
KEV EPSS 57.2% 7.2

This vulnerability allows authenticated attackers to execute arbitrary code on Ivanti Endpoint Manager Mobile (EPMM) systems by sending specially craf...

May 13, 2025
CVE-2025-29039
7.2

This vulnerability allows remote attackers to execute arbitrary code on D-Link DIR-832x routers via a specific function (0x41dda8). It affects users o...

Apr 17, 2025
CVE-2024-50960
7.2

A command injection vulnerability in the Nmap diagnostic tool within Extron SMP/SME admin web consoles allows authenticated attackers to execute arbit...

Apr 15, 2025
CVE-2025-30067
7.2

This CVE describes a code injection vulnerability in Apache Kylin where attackers with admin access can modify JDBC connection configurations to execu...

Mar 27, 2025
CVE-2024-54448
7.2

This vulnerability allows authenticated attackers with administrator privileges or explicit Automation Scripting access to execute arbitrary system co...

Mar 14, 2025
CVE-2024-11600
7.2

This vulnerability allows authenticated WordPress administrators to execute arbitrary code on servers running the Borderless plugin. Attackers with ad...

Jan 30, 2025
CVE-2024-36694
7.2

OpenCart 4.0.2.3 contains a Server-Side Template Injection vulnerability in the Theme Editor function that allows authenticated attackers to execute a...

Dec 18, 2024
CVE-2024-11620
7.2

This vulnerability in Rank Math SEO WordPress plugin allows attackers to inject arbitrary code into .htaccess files, potentially leading to remote cod...

Nov 28, 2024
CVE-2024-53268
7.2

This vulnerability in Joplin note-taking app allows attackers to achieve remote code execution on Windows systems by exploiting unfiltered URI schemes...

Nov 25, 2024

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,183 CVEs classified as CWE-94, with 539 rated critical and 525 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free