Skip to main content

About CWE-94

Injected code can alter control flow and often leads to arbitrary code execution. It can also reach resources the attacker is otherwise blocked from, bypass authentication logic and run without being logged.

MITRE name
Improper Control of Generation of Code ('Code Injection')
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft
Also known as
Code Injection

Mitigations

  • +Refactor the program so it does not need to generate code dynamically.
  • +Validate input with stringent allowlists that limit which language constructs are permitted.
  • +Run the code in a sandbox or jail that restricts what it can execute.
  • +Use an environment with automatic taint propagation that blocks execution involving unvalidated variables.
  • +Test with fuzzing and fault injection to find inputs that reach code generation paths.

Detection
Automated static analysis (SAST) is rated highly effective for this weakness by tracing input sources into code generation sinks.

CWE-94 Vulnerabilities

39 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-65660
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft8.82.1%KEV2026-08-11
CVE-2026-60004
Gitea Code Injection Vulnerability
Gitea9.824.0%KEV2026-08-26
CVE-2026-72530
TrueConf Server Code Injection Vulnerability
TrueConf9.51.7%KEV2026-08-19
CVE-2025-62593
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
ray-project9.462.5%KEV2025-11-26
CVE-2026-9198
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
IBM9.828.7%KEV2026-07-17
CVE-2026-15410
SonicWall SMA1000 Appliances Code Injection Vulnerability
SonicWall7.211.8%KEV2026-07-14
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Apache Software Foundation8.815.5%KEV2026-04-07
CVE-2026-1340
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti9.898.6%KEV2026-01-29
CVE-2026-33017
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
langflow-ai9.324.8%KEV2026-03-20
CVE-2025-32432
Craft CMS Allows Remote Code Execution
craftcms10.099.8%KEV2025-04-25
CVE-2025-54068
Livewire vulnerable to remote command execution during property update hydration
livewire9.297.3%KEV2025-07-17
CVE-2026-1281
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti9.898.7%KEV2026-01-29
CVE-2025-6204
Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
Dassault Systèmes8.079.3%KEV2025-08-04
CVE-2025-49704
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft8.8100.0%KEV2025-07-08
CVE-2024-56145
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
craftcms9.397.4%KEV2024-12-18
CVE-2025-4428
Remote Code Execution
Ivanti7.286.5%KEV2025-05-13
CVE-2025-1976
Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6
Brocade8.60.7%KEV2025-04-24
CVE-2025-23209
Potential RCE with a compromised security key in craft/cms
craftcms8.121.8%KEV2025-01-18
CVE-2022-24816
Improper Control of Generation of Code in jai-ext
geosolutions-it10.099.9%KEV2022-04-13
CVE-2023-24955
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft7.285.0%KEV2023-05-09
CVE-2021-44529
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
-9.899.1%KEV2021-12-08
CVE-2024-21351
Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft7.627.8%KEV2024-02-13
CVE-2023-6548
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Cloud Software Group5.53.2%KEV2024-01-17
CVE-2018-14667
Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
-9.874.2%KEV2018-11-06
CVE-2023-33246
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
Apache Software Foundation9.896.6%KEV2023-05-24
CVE-2023-3519
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability
Citrix9.899.7%KEV2023-07-19
CVE-2021-39144
XStream is vulnerable to a Remote Command Execution attack
x-stream8.598.1%KEV2021-08-23
CVE-2022-22963
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
-9.899.9%KEV2022-04-01
CVE-2022-22947
VMware Spring Cloud Gateway Code Injection Vulnerability
-10.098.3%KEV2022-03-03
CVE-2022-22965
Spring Framework JDK 9+ Remote Code Execution Vulnerability
-9.899.6%KEV2022-04-01
CVE-2018-1273
VMware Tanzu Spring Data Commons Property Binder Vulnerability
Spring by Pivotal9.897.0%KEV2018-04-11
CVE-2020-8218
Pulse Connect Secure Code Injection Vulnerability
-7.232.3%KEV2020-07-30
CVE-2019-7609
Kibana Arbitrary Code Execution
Elastic9.895.3%KEV2019-03-25
CVE-2020-8243
Ivanti Pulse Connect Secure Code Execution Vulnerability
-7.290.8%KEV2020-09-29
CVE-2021-22894
Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability
-8.841.3%KEV2021-05-27
CVE-2021-22900
Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
-7.214.1%KEV2021-05-27
CVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
GitLab9.460.2%2026-08-17
CVE-2026-4257
Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality
supsysticcom9.832.8%2026-03-30
CVE-2026-58138
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
conductor-oss9.814.7%2026-06-30

Frequently Asked Questions

What is CWE-94 code injection?→

CWE-94 is a weakness where outside input is placed into code the product generates, without neutralizing syntax that changes how that code behaves.

Is every remote code execution bug a CWE-94?→

No. MITRE notes that code execution is a technical impact that dozens of weaknesses can cause. CWE-94 fits only when the product deliberately constructs code from input.

How many exploited vulnerabilities are classified as CWE-94?→

This database lists 39 CVE records mapped to CWE-94 by their CVE Numbering Authority. 36 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 6 to known ransomware campaigns. Examples include CVE-2026-65660, CVE-2026-60004, CVE-2026-72530.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.