Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.
A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a ma
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the
Code Injection in GitHub repository getgrav/grav prior to 1.7.34.
custom-content-type-manager Wordpress plugin can be used by an administrator to achieve arbitrary PHP remote code execut
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has
Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to exe
Azure Site Recovery Remote Code Execution Vulnerability
DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.
The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allo
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the co
The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allo
LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/th
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and ac
Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older tha
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that e
Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authentic
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbit
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbit
A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run ar
All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructo
SwiftTerm is a Xterm/VT100 Terminal emulator. Prior to commit a94e6b24d24ce9680ad79884992e1dff8e150a31, an attacker coul
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execu
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to
Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0,
Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms V
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and al
Code Injection in GitHub repository publify/publify prior to 9.2.8.
super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spl
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided argu
.NET and Visual Studio Remote Code Execution Vulnerability
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is
A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. T
A vulnerability classified as critical was found in Simple Ads Manager Plugin. This vulnerability affects unknown code.
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR managemen
A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the f
October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability
Frequently Asked Questions
What is CWE-94?
CWE-94 (CWE-94) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-94?
There are 7,397 CVE records associated with CWE-94 in our database. Of these, 1309 are critical severity, 1598 are high severity, and 855 are medium severity.
How can I protect against CWE-94 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-94 using AI-powered security agents.
Detect CWE-94 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-94 vulnerabilities across your infrastructure.
Get Started