CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,185
Total CVEs
540
Critical
526
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 11
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Ivanti 8
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,185)

CVE-2024-11620
7.2

This vulnerability in Rank Math SEO WordPress plugin allows attackers to inject arbitrary code into .htaccess files, potentially leading to remote cod...

Nov 28, 2024
CVE-2024-53268
7.2

This vulnerability in Joplin note-taking app allows attackers to achieve remote code execution on Windows systems by exploiting unfiltered URI schemes...

Nov 25, 2024
CVE-2024-9162
7.2

This vulnerability allows authenticated WordPress administrators to inject arbitrary PHP code into export files created by the All-in-One WP Migration...

Oct 28, 2024
CVE-2024-50611
7.2

CVE-2024-50611 is a code execution vulnerability in CycloneDX cdxgen where processing untrusted codebases may execute malicious code from build files ...

Oct 27, 2024
CVE-2024-48700
7.2

CVE-2024-48700 is an arbitrary code execution vulnerability in Kliqqi-CMS that allows attackers to execute malicious code on affected systems via the ...

Oct 25, 2024
CVE-2024-40442
7.2

This vulnerability in Doccano's annotation tools allows remote attackers to escalate privileges through crafted REST requests. It affects Doccano v1.8...

Sep 23, 2024
CVE-2024-44724
7.2

AutoCMS v5.4 contains a PHP code injection vulnerability in the txtsite_url parameter at /admin/site_add.php, allowing attackers to execute arbitrary ...

Sep 9, 2024
CVE-2024-37382
7.2

This vulnerability allows attackers to execute arbitrary code on Ab Initio Metadata Hub and Authorization Gateway servers by exploiting the import hos...

Aug 8, 2024
CVE-2024-22274
7.2

CVE-2024-22274 is an authenticated remote code execution vulnerability in VMware vCenter Server. Attackers with administrative shell access on the vCe...

May 21, 2024
CVE-2024-3892
7.2

A local code execution vulnerability in Telerik UI for WinForms allows untrusted theme assemblies to execute arbitrary code on Windows systems. This a...

May 15, 2024
CVE-2024-22722
7.2

This Server-Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to execute arbitrary commands by injecting malicious tem...

Apr 11, 2024
CVE-2024-22188
7.2

This CVE describes a command injection vulnerability in TYPO3's Install Tool that allows authenticated admin users with system maintainer privileges t...

Mar 5, 2024
CVE-2024-21682
7.2

This high-severity injection vulnerability (CWE-94) in Assets Discovery versions 1.0 through 6.2.0 allows authenticated attackers to modify system cal...

Feb 20, 2024
CVE-2024-1297
7.2

CVE-2024-1297 is an OS command injection vulnerability in Loomio version 2.22.0 that allows attackers to execute arbitrary commands on the server. Thi...

Feb 20, 2024
CVE-2024-25298
7.2

CVE-2024-25298 is a critical code injection vulnerability in REDAXO CMS version 5.15.1 that allows attackers to execute arbitrary code on affected sys...

Feb 17, 2024
CVE-2024-25301
7.2

CVE-2024-25301 is a remote code execution vulnerability in Redaxo CMS v5.15.1 that allows attackers to execute arbitrary code via the /pages/templates...

Feb 14, 2024
CVE-2023-31037
7.2

This vulnerability allows root users on NVIDIA Bluefield DPU BMC systems to inject and execute arbitrary code through ipmitool network calls. It affec...

Jan 24, 2024
CVE-2023-46865
7.2

This vulnerability allows authenticated superadmin users in Crater invoice software to execute arbitrary PHP code by embedding malicious code within P...

Oct 30, 2023
CVE-2023-46818
7.2

This vulnerability allows authenticated ISPConfig administrators to inject arbitrary PHP code through the language file editor when the admin_allow_la...

Oct 27, 2023
CVE-2023-30912
7.2

CVE-2023-30912 is a remote code execution vulnerability in HPE OneView that allows attackers to execute arbitrary code on affected systems. This affec...

Oct 25, 2023
CVE-2023-44847
7.2

This vulnerability in SeaCMS v12.8 allows attackers to execute arbitrary code through the admin_Weixin.php component. It affects all systems running t...

Oct 10, 2023
CVE-2023-3551
7.2

This CVE-2023-3551 is a code injection vulnerability in TeamPass password manager software that allows attackers to execute arbitrary code on affected...

Jul 8, 2023
CVE-2023-36992
7.2

This vulnerability allows remote attackers to inject and execute arbitrary PHP code through the config editor in TravianZ admin pages. It affects Trav...

Jul 7, 2023
CVE-2023-3393
7.2

CVE-2023-3393 is a code injection vulnerability in fossbilling that allows attackers to execute arbitrary code on affected systems. This affects all f...

Jun 23, 2023
CVE-2023-30179
7.2

CVE-2023-30179 is a Server-Side Template Injection vulnerability in CraftCMS that allows authenticated attackers to inject Twig templates into the Use...

Jun 13, 2023
CVE-2023-32540
7.2

This vulnerability in Advantech WebAccess/SCADA allows attackers to overwrite any file on the operating system, potentially leading to arbitrary code ...

Jun 6, 2023
CVE-2023-24955
7.2

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by sending specially crafted requests. It affects ...

May 9, 2023
CVE-2023-29963
7.2

S-CMS v5.0 contains an authenticated remote code execution vulnerability in the /admin/ajax.php component. Attackers with admin credentials can execut...

May 5, 2023
CVE-2022-36963
7.2

This command injection vulnerability in SolarWinds Platform allows authenticated administrators to execute arbitrary system commands. Attackers with c...

Apr 21, 2023
CVE-2023-25549
7.2

This vulnerability allows remote code execution through code injection in the DCE network settings endpoint of StruxureWare Data Center Expert. Attack...

Apr 18, 2023
CVE-2023-24835
7.2

This vulnerability allows authenticated administrators in Softnext Technologies Corp.'s SPAM SQR to inject malicious code through a specific function,...

Mar 27, 2023
CVE-2015-3173
7.2

This vulnerability in the Custom Content Type Manager WordPress plugin allows authenticated administrators to execute arbitrary PHP code remotely. It ...

Jul 6, 2022
CVE-2022-2073
7.2

CVE-2022-2073 is a code injection vulnerability in Grav CMS that allows attackers to execute arbitrary code on affected systems. This affects Grav ins...

Jun 29, 2022
CVE-2022-0661
7.2

The Ad Injection WordPress plugin through version 1.2.0.19 contains a critical vulnerability that allows authenticated administrators to inject arbitr...

Apr 18, 2022
CVE-2022-26982
7.2

This vulnerability allows remote authenticated administrators in SimpleMachinesForum to execute arbitrary PHP code by modifying themes. It affects Sim...

Apr 5, 2022
CVE-2022-24734
7.2

This vulnerability allows authenticated administrators with settings management permissions to inject PHP code into MyBB forum settings, leading to re...

Mar 9, 2022
CVE-2021-43944
7.2

This vulnerability allows remote attackers with system administrator permissions in Atlassian Jira Server and Data Center to execute arbitrary code vi...

Mar 8, 2022
CVE-2021-44238
7.2

AyaCMS 3.1.2 contains a remote code execution vulnerability in the admin module that allows attackers to execute arbitrary code on the server. This af...

Mar 1, 2022
CVE-2021-46118
7.2

CVE-2021-46118 is a remote code execution vulnerability in JPress 4.2.0 that allows attackers to inject malicious code through email template editing ...

Jan 26, 2022
CVE-2021-46117
7.2

CVE-2021-46117 is a remote code execution vulnerability in JPress 4.2.0 that allows authenticated attackers to inject malicious code via email templat...

Jan 26, 2022
CVE-2021-24537
7.2

This vulnerability allows high-privilege WordPress users (administrators/editors) to execute arbitrary PHP code via the Similar Posts plugin widget se...

Nov 8, 2021
CVE-2021-43281
7.2

This vulnerability allows authenticated MyBB administrators with 'Can manage settings?' permission to inject and execute arbitrary PHP code through th...

Nov 4, 2021
CVE-2021-25877
7.2

CVE-2021-25877 is an insecure file write vulnerability in AVideo/YouPHPTube that allows authenticated administrators to write arbitrary files to the s...

Nov 1, 2021
CVE-2021-41619
7.2

CVE-2021-41619 is a remote code execution vulnerability in Gradle Enterprise that allows attackers with administrative access to execute arbitrary com...

Oct 27, 2021
CVE-2021-39402
7.2

MaianAffiliate v1.0 suffers from code injection vulnerability in the admin product addition feature. This allows attackers to inject malicious code th...

Sep 20, 2021
CVE-2021-39503
7.2

CVE-2021-39503 is a remote code execution vulnerability in PHPMyWind 5.6 that allows attackers to inject PHP code into configuration files due to insu...

Sep 7, 2021
CVE-2021-37626
7.2

This vulnerability allows untrusted back-end users in Contao CMS to execute arbitrary PHP code via insert tags. It affects installations where back-en...

Aug 11, 2021
CVE-2021-24430
7.2

This vulnerability in the Speed Booster Pack WordPress plugin allows remote code execution (RCE) due to improper input validation. Attackers can injec...

Aug 2, 2021
CVE-2021-22900
7.2

This vulnerability in Pulse Connect Secure allows authenticated administrators to upload malicious archives that can write arbitrary files to the syst...

May 27, 2021
CVE-2021-24209
7.2

This vulnerability allows authenticated WordPress administrators (or users with admin privileges) to execute arbitrary code on servers running vulnera...

Apr 5, 2021

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,185 CVEs classified as CWE-94, with 540 rated critical and 526 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free