Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-1119 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.5 - Unauthenticated Arbitrary Shortcode Execution — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin 7.3 High2025-03-13
CVE-2025-27407 Remote code execution when loading a crafted GraphQL schema — graphql-ruby 9.1 Critical2025-03-12
CVE-2025-1550 Arbitrary Code Execution via Crafted Keras Config for Model Loading — Keras 7.8 -2025-03-11
CVE-2025-2169 WPCS – WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution — WPCS – WordPress Currency Switcher Professional 7.3 High2025-03-11
CVE-2025-26936 WordPress Fresh Framework plugin <= 1.70.0 - Unauthenticated Remote Code Execution (RCE) vulnerability — Fresh Framework 10.0 Critical2025-03-10
CVE-2025-1497 Remote Code Execution in PlotAI — PlotAI 9.8 -2025-03-10
CVE-2024-13895 Code Snippets CPT <= 2.1.0 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — Code Snippets CPT 4.3 Medium2025-03-08
CVE-2024-13890 Allow PHP Execute <= 1.0 - Authenticated (Editor+) PHP Code Injection — Allow PHP Execute 7.2 High2025-03-08
CVE-2024-13815 Listingo - Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution — Listingo 6.5 Medium2025-03-05
CVE-2025-26970 WordPress Ark Theme Core plugin < 1.71.0 - Unauthenticated Remote Code Execution (RCE) vulnerability — Ark Theme Core 10.0 Critical2025-03-03
CVE-2024-53382 Prism 代码注入漏洞 — Prism 4.9 Medium2025-03-03
CVE-2024-53386 stage.js 代码注入漏洞 — Stage.js 4.9 Medium2025-03-03
CVE-2024-13806 Authors List <= 2.0.6 - Unauthenticated Arbitrary Shortcode Execution — Authors List 6.5 Medium2025-03-01
CVE-2025-27554 ToDesktop 代码注入漏洞 — ToDesktop 9.9 Critical2025-03-01
CVE-2024-52925 OPSWAT MetaDefender KIOSK 代码注入漏洞 — MetaDefender Kiosk 6.8 Medium2025-02-26
CVE-2025-1510 Custom Post Type Date Archives <= 2.7.1 - Missing Authorization to Unauthenticated Arbitrary Shortcode Execution — Custom Post Type Date Archives 7.3 High2025-02-22
CVE-2025-1509 Show Me The Cookies <= 1.0 - Unauthenticated Arbitrary Shortcode Execution — Show Me The Cookies 7.3 High2025-02-22
CVE-2024-13900 Head, Footer and Post Injections <= 3.3.0 - Authenticated (Administrator+) PHP Code Injection in Multisite Environments — Head, Footer and Post Injections 4.1 Medium2025-02-21
CVE-2025-0161 IBM Security Verify Access Appliance code injection — Security Verify Access 7.8 High2025-02-20
CVE-2024-13792 WooCommerce Food - Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids — WooCommerce Food - Restaurant Menu & Food ordering 7.3 High2025-02-20
CVE-2025-1465 lmxcms Maintenance db.inc.php code injection — lmxcms 4.1 Medium2025-02-19
CVE-2024-13689 Uncode Core <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary Shortcode Execution in uncode_get_medias — Uncode Core 6.3 Medium2025-02-18
CVE-2024-13797 PressMart - Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution — PressMart - Modern Elementor WooCommerce WordPress Theme 7.3 High2025-02-18
CVE-2025-1302 JSONPath Plus 安全漏洞 — jsonpath-plus 9.8 Critical2025-02-15
CVE-2024-13345 Avada Builder <= 3.11.13 - Unauthenticated Arbitrary Shortcode Execution — Avada (Fusion) Builder 7.3 High2025-02-13
CVE-2024-13346 Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution — Avada | Website Builder For WordPress & WooCommerce 7.3 High2025-02-13
CVE-2024-13814 Global Gallery - WordPress Responsive Gallery <= 9.1.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution — Global Gallery - WordPress Responsive Gallery 5.4 Medium2025-02-12
CVE-2024-10644 Ivanti Connect Secure 代码注入漏洞 — Connect Secure 9.1 Critical2025-02-11
CVE-2024-7425 WP All Export Pro <= 1.9.1 - Authenticated (ShopManager+) Arbtirary Options Update — WP All Export Pro 6.8 Medium2025-02-07
CVE-2024-7419 WP All Export Pro <= 1.9.1 - Unauthenticated Remote Code Execution via Custom Export Fields — WP All Export Pro 8.3 High2025-02-07

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.