CWE-78


Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.


We have discovered 235,022 live websites that are affected by CWE-78.

Contact us to get more info









CVEs

  • Count - 59



Website Distribution by Country

Number of websites using CWE-78
United States41,401 websites



France79,905 websites
Russia14,477 websites
Germany11,388 websites
Netherlands7,448 websites
Brazil7,372 websites
Italy6,771 websites
Poland5,124 websites
GB4,563 websites
Spain4,345 websites

Website Distribution by TLD

Number of websites using CWE-78
.com80,626 websites
.fr33,198 websites
.ru12,471 websites
.org9,890 websites
.net7,157 websites
.de6,740 websites
.nl6,637 websites
.com.br6,194 websites
.it5,233 websites
.be4,765 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-78
DiscoveredCVEDescriptionWebsites
Jul, 2026CVE-2026-55420 Discourse: Remote code execution via pdf uploads1,107
Jun, 2026CVE-2026-55697 pnpm: Repository-controlled configDependencies can select a pacquet native install engine1
Jun, 2026CVE-2026-40079 Cacti: Command Injection via escape_command() no-op in RRDtool execution74
Jun, 2026CVE-2026-47294 Microsoft SharePoint Server Remote Code Execution Vulnerability3,020
Apr, 2026CVE-2026-41247 elFinder: Command injection in resize background color parameter when using ImageMagick CLI28
Apr, 2026CVE-2026-23500 Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration350
Apr, 2026CVE-2026-35196 Chamilo LMS has OS Command Injection via export_all_certificates action5
Apr, 2026CVE-2026-32892 OS Command Injection in Chamilo LMS 1.11.3611
Mar, 2026CVE-2026-33046 Indico discloses local files resulting in Remote Code Execution through LaTeX injection62
Mar, 2026CVE-2025-50193 Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database parameter11
List of the most common CVEs that are part of CWE-78
DiscoveredCVEDescriptionWebsites
Oct, 2024CVE-2024-8926 PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass)199,450
Jun, 2024CVE-2024-4577 Argument Injection in PHP-CGI165,946
Nov, 2025CVE-2025-9501 W3 Total Cache < 2.8.13 - Unauthenticated Command Injection16,496
Oct, 2024CVE-2024-45720 Apache Subversion: Command line argument injection on Windows platforms5,512
May, 2024CVE-2024-2662 Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command Injection3,591
Jun, 2026CVE-2026-47294 Microsoft SharePoint Server Remote Code Execution Vulnerability3,020
Feb, 2026CVE-2025-12122 Popup Box – Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting1,707
Jul, 2026CVE-2026-55420 Discourse: Remote code execution via pdf uploads1,107
Aug, 2024CVE-2024-39401 Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)825
Aug, 2024CVE-2024-39402 Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)825

Websites affected by CWE-78

Top websites that are affected by CWE-78. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.****.com United States***
****************.com United States*,***
********.********.it Italy*,***
*******.com Germany*,***
***.int Switzerland*,***
**********.dk Denmark*,***
******.gov United States*,***
*********.com United States*,***
***************.org United States*,***
***.de Germany*,***
See full domain list