Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-94 (对生成代码的控制不恰当(代码注入)) — Vulnerability Class 1295

1295 vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-4998 Sinaptik AI PandasAI Chat Message code_executor.py CodeExecutor.execute code injection — PandasAI 7.3 High2026-03-28
CVE-2026-33943 Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code — happy-dom 8.8 High2026-03-27
CVE-2026-33940 Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial — handlebars.js 8.1 High2026-03-27
CVE-2026-33938 Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block — handlebars.js 8.1 High2026-03-27
CVE-2026-33881 Windmill: Rogue Workspace Admins can inject code via unescaped workspace environment variable interpolation in NativeTS executor — windmill 4.8 -2026-03-27
CVE-2026-33873 Langflow has Authenticated Code Execution in Agentic Assistant Validation — langflow 8.8 -2026-03-27
CVE-2026-33654 Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling — nanobot 10.0 -2026-03-27
CVE-2026-4963 huggingface smolagents Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_with code injection — smolagents 6.3 Medium2026-03-27
CVE-2025-15616 Wazuh Agent and Manager OS Command Injection and Untrusted Search Path — wazuh-agent 6.7 Medium2026-03-27
CVE-2026-32669 BUFFALO Wi-Fi router 代码注入漏洞 — BUFFALO Wi-Fi router products 9.8 -2026-03-27
CVE-2026-33744 BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml — BentoML 7.8 High2026-03-27
CVE-2026-33622 A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution — pinchtab 6.3 -2026-03-26
CVE-2026-33660 n8n Has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode — n8n 8.8 -2026-03-25
CVE-2026-32573 WordPress Nelio AB Testing plugin <= 8.2.7 - Remote Code Execution (RCE) vulnerability — Nelio AB Testing 8.8 -2026-03-25
CVE-2026-32525 WordPress JetFormBuilder plugin <= 3.5.6.1 - Remote Code Execution (RCE) vulnerability — JetFormBuilder 9.8 -2026-03-25
CVE-2026-27044 WordPress Total Poll Lite plugin <= 4.12.0 - Remote Code Execution (RCE) vulnerability — Total Poll Lite 9.9 Critical2026-03-25
CVE-2026-25447 WordPress Widget Wrangler plugin <= 2.3.9 - Remote Code Execution (RCE) vulnerability — Widget Wrangler 9.1 Critical2026-03-25
CVE-2026-25366 WordPress Woody ad snippets plugin <= 2.7.1 - Remote Code Execution (RCE) vulnerability — Woody ad snippets 9.9 Critical2026-03-25
CVE-2026-25001 WordPress Post Snippets plugin <= 4.0.12 - Remote Code Execution (RCE) vulnerability — Post Snippets 8.5 High2026-03-25
CVE-2026-33336 Vikunja Desktop vulnerable to Remote Code Execution via same-window navigation — vikunja 9.6 -2026-03-24
CVE-2026-33334 Vikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegration — vikunja 9.0 -2026-03-24
CVE-2026-4745 Arbitrary Code Execution via Crafted Bytecode in dendibakh/perf-ninja — perf-ninja 9.8 -2026-03-24
CVE-2026-4681 Critical Remote Code Execution vulnerability reported in Windchill — Windchill PDMLink 9.8 -2026-03-23
CVE-2026-32276 Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin — connect-cms 8.8 High2026-03-23
CVE-2026-33479 AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin — AVideo 8.8 High2026-03-23
CVE-2025-10679 ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution — ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema 7.3 High2026-03-23
CVE-2026-4564 yangzongzhuan RuoYi Quartz Job job code injection — RuoYi 4.7 Medium2026-03-22
CVE-2026-4515 Foundation Agents MetaGPT operator.py code_generate code injection — MetaGPT 6.3 Medium2026-03-21
CVE-2026-4004 Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'task_id' Parameter — Task Manager 6.5 Medium2026-03-21
CVE-2024-13785 Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.7.2 - Unauthenticated Blind Arbitrary Shortcode Execution — Contact Form, Survey, Quiz & Popup Form Builder – ARForms 5.6 Medium2026-03-21

Vulnerabilities classified as CWE-94 (对生成代码的控制不恰当(代码注入)) represent 1295 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.