CWE-95— Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection)
127 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-95page 1 of 3
- CVE-2011-10033CRITICALCVSS 9.3EG 0.02025-10-15
The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter is set to 'log-reset'. The root cause is unsafe use of ev…
- CVE-2013-10051CRITICALCVSS 9.8EG 9.82025-08-01
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP e…
- CVE-2013-10070CRITICALCVSS 10.0EG 0.02025-08-05
PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A remote attacker can exploit this flaw by crafting a request that i…
- CVE-2019-9507HIGHCVSS 8.3EG 8.32020-03-30
The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the application incorrectly neutralizes code syntax before executing. Since all commands within the web application are executed a…
- CVE-2020-37137MEDIUMCVSS 6.1EG 6.12026-02-05
PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerabi…
- CVE-2020-5217MEDIUMCVSS 4.4EG 4.42020-01-23
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_directives, a semicolon c…
- CVE-2020-5256HIGHCVSS 7.9EG 7.92020-03-09
BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the permissions of the PHP pro…
- CVE-2020-6650HIGHCVSS 8.3EG 8.32020-03-23
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update…
- CVE-2021-23277HIGHCVSS 8.3EG 10.02021-04-13
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in loadUserFile function…
- CVE-2021-33678MEDIUMCVSS 6.5EG 6.52021-07-14
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be execut…
- CVE-2022-36010CRITICALCVSS 10.0EG 10.02022-08-15
This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/09a0ca97835b0834ad054563e2fddc6f22bc5d8c/src/components/JsonFunc…
- CVE-2022-36099CRITICALCVSS 9.9EG 9.92022-09-08
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax incl…
- CVE-2022-36100CRITICALCVSS 9.9EG 9.92022-09-08
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tag…
- CVE-2022-38193MEDIUMCVSS 6.1EG 9.62022-08-16
There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution.
- CVE-2022-40871CRITICALCVSS 9.8EG 9.82022-10-12
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it b…
- CVE-2022-41928CRITICALCVSS 9.9EG 9.92022-11-23
XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` mac…
- CVE-2022-41931CRITICALCVSS 9.9EG 9.92022-11-23
xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrar…
- CVE-2023-0089HIGHCVSS 8.8EG 8.82023-03-08
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below.
- CVE-2023-0090CRITICALCVSS 9.8EG 9.82023-03-08
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such…
- CVE-2023-0888MEDIUMCVSS 4.9EG 7.22023-03-13
An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. An aut…
- CVE-2023-26323HIGHCVSS 7.6EG 7.62024-08-28
A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.
- CVE-2023-26477CRITICALCVSS 10.0EG 10.02023-03-02
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter),…
- CVE-2023-29209CRITICALCVSS 9.9EG 9.92023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Vel…
- CVE-2023-29210CRITICALCVSS 9.9EG 9.92023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Veloci…
- CVE-2023-29211CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki i…
- CVE-2023-29212CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cau…
- CVE-2023-29214CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cau…
- CVE-2023-29509CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the…
- CVE-2023-29511CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading…
- CVE-2023-30537CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full acce…
- CVE-2023-35150CRITICALCVSS 9.9EG 9.92023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute cod…
- CVE-2023-35152CRITICALCVSS 9.9EG 9.92023-06-23
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their first name field and see it executed with programming rights. L…
- CVE-2023-37462CRITICALCVSS 9.9EG 9.92023-07-14
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to program…
- CVE-2023-37909CRITICALCVSS 9.9EG 9.92023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arb…
- CVE-2023-40177CRITICALCVSS 9.9EG 9.92023-08-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus ef…
- CVE-2023-46731CRITICALCVSS 10.0EG 10.02023-11-06
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the code for displaying administration sections. This allows a…
- CVE-2023-48699HIGHCVSS 8.4EG 8.42023-11-21
fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker could modify the locators.ini locator file with python code that without proper validatio…
- CVE-2023-50447HIGHCVSS 8.1EG 8.12024-01-19
Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).
- CVE-2023-50721CRITICALCVSS 9.9EG 9.92023-12-15
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowi…
- CVE-2023-50723CRITICALCVSS 9.9EG 9.92023-12-15
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missi…
- CVE-2023-6735HIGHCVSS 8.8EG 8.82024-01-12
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
- CVE-2023-7101HIGHCVSS 7.8EG 9.0⚠ KEV2023-12-24
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type ��…
- CVE-2023-7224HIGHCVSS 7.8EG 7.82024-01-08
OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable
- CVE-2023-7245HIGHCVSS 7.8EG 7.82024-02-20
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment v…
- CVE-2024-10633HIGHCVSS 7.3EG 7.32025-01-26
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including,…
- CVE-2024-21650CRITICALCVSS 10.0EG 10.02024-01-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to ex…
- CVE-2024-27320HIGHCVSS 7.8EG 7.82024-09-12
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided CSV files. If a victim user creates a classification task using a mali…
- CVE-2024-27321HIGHCVSS 7.8EG 7.82024-09-12
An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle provided CSV files. If a user creates a multilabel classification ta…
- CVE-2024-31465CRITICALCVSS 9.9EG 9.92024-04-10
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type `XWiki.Searc…
- CVE-2024-31982CRITICALCVSS 10.0EG 10.02024-04-10
XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code exe…
Map vulnerabilities like CWE-95 to your infrastructure
EchelonGraph correlates every CVE — across CWE-95 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →