CWE-94: Code Injection

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

1,187
Total CVEs
540
Critical
528
High
8.6
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
94
2025
389
2024
338
2023
179
2022
55

Top Affected Vendors

1 Microsoft 27
2 Apache 25
3 Nvidia 12
4 Xwiki 11
5 Fedoraproject 10
6 Seacms 10
7 Apple 9
8 Ivanti 8
9 Google 7
10 Craftcms 7

All Code Injection CVEs (1,187)

CVE-2025-64321
5.3

This vulnerability allows attackers to manipulate configuration files through improper input neutralization in Salesforce Agentforce Vibes Extension's...

Nov 4, 2025
CVE-2025-64318
5.3

This vulnerability allows attackers to manipulate LLM prompts to write malicious content to configuration files in Salesforce Mulesoft Anypoint Code B...

Nov 4, 2025
CVE-2025-48119
5.3

This vulnerability in the RS WP Book Showcase WordPress plugin allows attackers to execute arbitrary shortcodes through code injection. It affects all...

May 16, 2025
CVE-2025-47562
5.3

This CVE describes a code injection vulnerability in the MapSVG WordPress plugin that allows attackers to inject malicious code through improper input...

May 16, 2025
CVE-2023-51320
5.3

PHPJabbers Night Club Booking Software v1.0 has a CSV injection vulnerability in the Languages section Labels parameters field that allows attackers t...

Feb 20, 2025
CVE-2025-27218
EPSS 57.6% 5.3

CVE-2025-27218 is an insecure deserialization vulnerability in Sitecore Experience Manager (XM) and Experience Platform (XP) that allows remote attack...

Feb 20, 2025
CVE-2024-55918
5.3

This vulnerability in Graphics::ColorNames Perl package allows HTML injection when an attacker can place a malicious file in the current working direc...

Dec 13, 2024
CVE-2024-3958
5.3

This vulnerability in GitLab allows attackers to exploit a discrepancy between the web interface and git CLI to trick users into cloning malicious rep...

Aug 8, 2024
CVE-2025-36938
5.1

This CVE describes a fault injection vulnerability in U-Boot's append_uint32_le() function that could allow physical attackers to escalate privileges ...

Dec 11, 2025
CVE-2025-62416
5.1

Bagisto v2.3.7 has a Server-Side Template Injection vulnerability in product description rendering that allows authenticated attackers with product cr...

Oct 16, 2025
CVE-2024-14020
5.0

This CVE describes a prototype pollution vulnerability in carboneio carbone's Formatter Handler component. Attackers can remotely modify object protot...

Jan 7, 2026
CVE-2025-9489
5.0

The WP-Members Membership Plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to execute a...

Sep 9, 2025
CVE-2023-42404
4.9

This vulnerability in OneVision Workspace allows attackers to execute arbitrary Java Expression Language (EL) code, potentially leading to remote code...

Apr 28, 2025
CVE-2024-53386
4.9

CVE-2024-53386 is a DOM clobbering vulnerability in Stage.js that allows attackers to inject HTML elements that shadow the document.currentScript prop...

Mar 3, 2025
CVE-2024-37773
4.8

An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows authenticated administrators to inject arbitrary HTML code in admin screens. This...

Dec 16, 2024
CVE-2024-43922
4.8

This vulnerability allows unauthenticated attackers to execute arbitrary shortcodes in WordPress via the NitroPack plugin, leading to code injection. ...

Aug 29, 2024
CVE-2025-59302
4.7

Apache CloudStack contains a code injection vulnerability in six administrative APIs that allows authenticated administrators to execute arbitrary Jav...

Nov 27, 2025
CVE-2024-6946
4.7

This vulnerability in Flute CMS allows remote attackers to inject malicious code through the /admin/pages/list endpoint by manipulating the 'blocks' p...

Jul 21, 2024
CVE-2024-6940
4.7

This critical vulnerability in DedeCMS allows remote attackers to inject and execute arbitrary code through the article_template_rand.php file. It aff...

Jul 21, 2024
CVE-2025-53927
4.6

This vulnerability allows attackers to bypass sandbox restrictions in MaxKB by copying malicious files to executable directories using Python's shutil...

Jul 17, 2025
CVE-2024-51330
4.4

This vulnerability allows a local attacker to execute arbitrary code through the inter-process communication mechanism between Cura and CuraEngine pro...

Nov 15, 2024
CVE-2024-3924
4.4

This CVE describes a code injection vulnerability in the huggingface/text-generation-inference repository's GitHub Actions workflow. Attackers can exp...

May 30, 2024
CVE-2025-66436
4.3

An authenticated attacker with access to create or modify Terms and Conditions documents in Frappe ERPNext can inject malicious Jinja2 templates into ...

Dec 15, 2025
CVE-2025-66435
4.3

An authenticated attacker with Contract Template creation/modification privileges can inject malicious Jinja2 templates into the contract_terms field,...

Dec 15, 2025
CVE-2025-49250
4.3

This vulnerability in the Team Showcase WordPress plugin allows attackers to execute arbitrary shortcodes through code injection. It affects all WordP...

Jun 6, 2025
CVE-2024-13420
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to reset and modify plugin/theme settings due to missin...

May 2, 2025
CVE-2025-3982
4.3

This CVE describes a prototype pollution vulnerability in Sverchok 1.3.0's Set Property Mk2 Node. Attackers can remotely manipulate object prototypes ...

Apr 27, 2025
CVE-2025-32383
4.3

A reverse shell vulnerability in MaxKB's function library module allows privileged users to execute arbitrary code and establish remote shell access. ...

Apr 10, 2025
CVE-2024-13895
4.3

The Code Snippets CPT WordPress plugin allows authenticated attackers with Subscriber-level access or higher to execute arbitrary shortcodes due to im...

Mar 8, 2025
CVE-2026-1226
N/A

This CVE describes an Improper Control of Generation of Code vulnerability in Schneider Electric products that process TGML graphics files. Attackers ...

Feb 11, 2026
CVE-2026-24871
N/A

This CVE describes a code injection vulnerability in the Minecraft-Rcon-Manage software that allows attackers to execute arbitrary code on affected sy...

Jan 27, 2026
CVE-2026-24806
N/A

This CVE describes a code injection vulnerability in the quick-media library's SVG plugin when processing PNG files. Attackers can execute arbitrary c...

Jan 27, 2026
CVE-2026-24474
N/A

This vulnerability in Dioxus Components allows arbitrary JavaScript code execution through user-supplied input in the `use_animated_open` function. It...

Jan 24, 2026
CVE-2025-34433
EPSS 47.4% N/A

AVideo versions 14.3.1 through 20.0 contain an unauthenticated remote code execution vulnerability. Attackers can exploit predictable installation sal...

Dec 19, 2025
CVE-2025-68278
N/A

This vulnerability allows attackers who can control markdown file content (like blog posts) to execute arbitrary code on systems running vulnerable ve...

Dec 18, 2025
CVE-2025-13658
N/A

This vulnerability in Longwatch devices allows unauthenticated attackers to execute arbitrary code with SYSTEM-level privileges via HTTP GET requests ...

Dec 2, 2025
CVE-2025-61588
N/A

This vulnerability in RISC Zero's zkVM platform allows a malicious host to write arbitrary data to guest memory locations when the guest calls sys_rea...

Oct 2, 2025

About Code Injection (CWE-94)

The product constructs all or part of a code segment using externally-influenced input, but does not neutralize special elements that could modify the intended code segment.

Our database tracks 1,187 CVEs classified as CWE-94, with 540 rated critical and 528 rated high severity. The average CVSS score for Code Injection vulnerabilities is 8.6.

External reference: View CWE-94 on MITRE CWE →

Monitor Code Injection Vulnerabilities

Get alerted when new Code Injection CVEs affect your infrastructure.

Start Monitoring Free