Code Injection (CWE-94)
CWE-94 describes a product that builds all or part of a code segment from outside input without neutralizing elements that change the syntax or behavior of that code. It applies only when the product intentionally constructs code. MITRE warns that this entry is often misused for any vulnerability whose impact is code execution, which by itself does not identify the root cause.
About CWE-94
Injected code can alter control flow and often leads to arbitrary code execution. It can also reach resources the attacker is otherwise blocked from, bypass authentication logic and run without being logged.
Mitigations
- +Refactor the program so it does not need to generate code dynamically.
- +Validate input with stringent allowlists that limit which language constructs are permitted.
- +Run the code in a sandbox or jail that restricts what it can execute.
- +Use an environment with automatic taint propagation that blocks execution involving unvalidated variables.
- +Test with fuzzing and fault injection to find inputs that reach code generation paths.
Detection
Automated static analysis (SAST) is rated highly effective for this weakness by tracing input sources into code generation sinks.
CWE-94 Vulnerabilities
39 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-65660 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 2.1% | KEV | 2026-08-11 |
| CVE-2026-60004 | Gitea Code Injection Vulnerability | Gitea | 9.8 | 24.0% | KEV | 2026-08-26 |
| CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | TrueConf | 9.5 | 1.7% | KEV | 2026-08-19 |
| CVE-2025-62593 | Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | ray-project | 9.4 | 62.5% | KEV | 2025-11-26 |
| CVE-2026-9198 | Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation | IBM | 9.8 | 28.7% | KEV | 2026-07-17 |
| CVE-2026-15410 | SonicWall SMA1000 Appliances Code Injection Vulnerability | SonicWall | 7.2 | 11.8% | KEV | 2026-07-14 |
| CVE-2026-34197 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans | Apache Software Foundation | 8.8 | 15.5% | KEV | 2026-04-07 |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Ivanti | 9.8 | 98.6% | KEV | 2026-01-29 |
| CVE-2026-33017 | Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint | langflow-ai | 9.3 | 24.8% | KEV | 2026-03-20 |
| CVE-2025-32432 | Craft CMS Allows Remote Code Execution | craftcms | 10.0 | 99.8% | KEV | 2025-04-25 |
| CVE-2025-54068 | Livewire vulnerable to remote command execution during property update hydration | livewire | 9.2 | 97.3% | KEV | 2025-07-17 |
| CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Ivanti | 9.8 | 98.7% | KEV | 2026-01-29 |
| CVE-2025-6204 | Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 | Dassault Systèmes | 8.0 | 79.3% | KEV | 2025-08-04 |
| CVE-2025-49704 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 8.8 | 100.0% | KEV | 2025-07-08 |
| CVE-2024-56145 | RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms | craftcms | 9.3 | 97.4% | KEV | 2024-12-18 |
| CVE-2025-4428 | Remote Code Execution | Ivanti | 7.2 | 86.5% | KEV | 2025-05-13 |
| CVE-2025-1976 | Code injection exposure in Fabric OS 9.1.0 through 9.1.1d6 | Brocade | 8.6 | 0.7% | KEV | 2025-04-24 |
| CVE-2025-23209 | Potential RCE with a compromised security key in craft/cms | craftcms | 8.1 | 21.8% | KEV | 2025-01-18 |
| CVE-2022-24816 | Improper Control of Generation of Code in jai-ext | geosolutions-it | 10.0 | 99.9% | KEV | 2022-04-13 |
| CVE-2023-24955 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 7.2 | 85.0% | KEV | 2023-05-09 |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability | - | 9.8 | 99.1% | KEV | 2021-12-08 |
| CVE-2024-21351 | Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft | 7.6 | 27.8% | KEV | 2024-02-13 |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Cloud Software Group | 5.5 | 3.2% | KEV | 2024-01-17 |
| CVE-2018-14667 | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability | - | 9.8 | 74.2% | KEV | 2018-11-06 |
| CVE-2023-33246 | Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function | Apache Software Foundation | 9.8 | 96.6% | KEV | 2023-05-24 |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | Citrix | 9.8 | 99.7% | KEV | 2023-07-19 |
| CVE-2021-39144 | XStream is vulnerable to a Remote Command Execution attack | x-stream | 8.5 | 98.1% | KEV | 2021-08-23 |
| CVE-2022-22963 | VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability | - | 9.8 | 99.9% | KEV | 2022-04-01 |
| CVE-2022-22947 | VMware Spring Cloud Gateway Code Injection Vulnerability | - | 10.0 | 98.3% | KEV | 2022-03-03 |
| CVE-2022-22965 | Spring Framework JDK 9+ Remote Code Execution Vulnerability | - | 9.8 | 99.6% | KEV | 2022-04-01 |
| CVE-2018-1273 | VMware Tanzu Spring Data Commons Property Binder Vulnerability | Spring by Pivotal | 9.8 | 97.0% | KEV | 2018-04-11 |
| CVE-2020-8218 | Pulse Connect Secure Code Injection Vulnerability | - | 7.2 | 32.3% | KEV | 2020-07-30 |
| CVE-2019-7609 | Kibana Arbitrary Code Execution | Elastic | 9.8 | 95.3% | KEV | 2019-03-25 |
| CVE-2020-8243 | Ivanti Pulse Connect Secure Code Execution Vulnerability | - | 7.2 | 90.8% | KEV | 2020-09-29 |
| CVE-2021-22894 | Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability | - | 8.8 | 41.3% | KEV | 2021-05-27 |
| CVE-2021-22900 | Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability | - | 7.2 | 14.1% | KEV | 2021-05-27 |
| CVE-2026-19478 | Improper Control of Generation of Code ('Code Injection') in GitLab | GitLab | 9.4 | 60.2% | 2026-08-17 | |
| CVE-2026-4257 | Contact Form by Supsystic <= 1.7.36 - Unauthenticated Server-Side Template Injection via Prefill Functionality | supsysticcom | 9.8 | 32.8% | 2026-03-30 | |
| CVE-2026-58138 | Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators | conductor-oss | 9.8 | 14.7% | 2026-06-30 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-94 code injection?→
CWE-94 is a weakness where outside input is placed into code the product generates, without neutralizing syntax that changes how that code behaves.
Is every remote code execution bug a CWE-94?→
No. MITRE notes that code execution is a technical impact that dozens of weaknesses can cause. CWE-94 fits only when the product deliberately constructs code from input.
How many exploited vulnerabilities are classified as CWE-94?→
This database lists 39 CVE records mapped to CWE-94 by their CVE Numbering Authority. 36 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 6 to known ransomware campaigns. Examples include CVE-2026-65660, CVE-2026-60004, CVE-2026-72530.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.