CWE-94Base41 in KEV

Improper Control of Generation of Code ('Code Injection')

Draft in the CWE catalog · 3,294 CVEs mapped

3,294
CVEs mapped
41
In KEV
6.6
Median CVSS
What it is

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Recent examples
6.5cvss
CVE-2026-12757

Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field

The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

MEDIUMno explanation yet
epss
3.5cvss
CVE-2026-86301

code-projects Hospital Information System Patient Management editPatient.php cross site scripting

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

LOWno explanation yet
epss
4.3cvss
CVE-2026-86294

SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting

A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

MEDIUMno explanation yet
epss
The record
Technical detail
CWE ID
CWE-94
Abstraction
Base
Structure
Simple
Status
Draft
References (2)