CWE-94: Code Injection — known CVE vulnerabilities
CVEs classified under CWE-94 (Code Injection), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-76605: Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
CVE-2026-76604: Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is…
CVE-2026-73299 — CVSS 10.0 (critical): Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated…
CVE-2026-67282: Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute…
CVE-2026-45618 — CVSS 10.0 (critical): LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with…
CVE-2026-58231 — CVSS 10.0 (critical): SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to…
CVE-2026-66915: Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by…
CVE-2026-64633: A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-65880: Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed…
CVE-2025-71389 — CVSS 10.0 (critical): Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose…
CVE-2026-44359 — CVSS 10.0 (critical): Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml…
CVE-2026-57811 — CVSS 10.0 (critical): Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna…
CVE-2026-61447 — CVSS 10.0 (critical): PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python…
CVE-2026-54769 — CVSS 10.0 (critical): Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical…
CVE-2026-10134 — CVSS 10.0 (critical): IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow…
CVE-2026-53576 — CVSS 10.0 (critical): Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API…
CVE-2026-10561 — CVSS 10.0 (critical): IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication…
CVE-2026-25470 — CVSS 10.0 (critical): Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows…
CVE-2026-52704 — CVSS 10.0 (critical): Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code…
CVE-2026-45132 — CVSS 10.0 (critical): CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow…
CVE-2026-45131 — CVSS 10.0 (critical): CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml)…
CVE-2026-43898 — CVSS 10.0 (critical): SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to…
CVE-2026-45829 — CVSS 10.0 (critical): A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated…
CVE-2026-44006 — CVSS 10.0 (critical): vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get…
CVE-2026-44005 — CVSS 10.0 (critical): vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic…
CVE-2026-43997 — CVSS 10.0 (critical): vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the…
CVE-2026-42288 — CVSS 10.0 (critical): ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication…
CVE-2026-42298 — CVSS 10.0 (critical): Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker…
CVE-2026-41196 — CVSS 10.0 (critical): Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a…
CVE-2026-40911 — CVSS 10.0 (critical): WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied…
CVE-2026-39337 — CVSS 10.0 (critical): ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in…
CVE-2026-28505 — CVSS 10.0 (critical): Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in…
CVE-2026-4745: Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This…
CVE-2026-26954 — CVSS 10.0 (critical): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping…
CVE-2026-27597 — CVSS 10.0 (critical): Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the…
CVE-2026-26216 — CVSS 10.0 (critical): Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a…
CVE-2026-25587 — CVSS 10.0 (critical): SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via…
CVE-2026-23830 — CVSS 10.0 (critical): SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being…
CVE-2026-24871: Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects…
CVE-2025-61937 — CVSS 10.0 (critical): The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of…
CVE-2026-22686 — CVSS 10.0 (critical): Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape…