CWE-94


Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.


We have discovered 1,503,676 live websites that are affected by CWE-94.

Contact us to get more info









CVEs

  • Count - 152



Website Distribution by Country

Number of websites using CWE-94
United States396,228 websites



Germany147,014 websites
Italy87,601 websites
France85,403 websites
GB67,052 websites
Spain51,050 websites
Netherlands41,874 websites
Japan41,137 websites
Russia37,562 websites
Poland36,718 websites

Website Distribution by TLD

Number of websites using CWE-94
.com625,917 websites
.de78,590 websites
.org62,419 websites
.it62,348 websites
.co.uk40,671 websites
.nl36,829 websites
.net34,408 websites
.fr33,345 websites
.com.br31,623 websites
.ru29,924 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-94
DiscoveredCVEDescriptionWebsites
Dec, 2025CVE-2025-13642 ProfilePress <= 4.16.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution49,753
Dec, 2025CVE-2024-32641 Masa CMS Vulnerable to Pre-Auth RCE via JSON API49
Dec, 2025CVE-2025-13486 Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form573
Dec, 2025CVE-2025-66294 Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass15
Dec, 2025CVE-2025-66299 Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMS15
Nov, 2025CVE-2025-13035 Code Snippets <= 3.9.1 - Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains15
Nov, 2025CVE-2025-7711 Classified Listing – Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Listing Description590
Nov, 2025CVE-2025-9334 Better Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code Injection11,871
Nov, 2025CVE-2025-6990 Kallyas <= 4.24.0 - Authenticated (Contributor+) Remote Code Execution12,401
Nov, 2025CVE-2025-10487 Advanced Ads <= 2.0.12 - Unauthenticated Limited Code Execution33,351
List of the most common CVEs that are part of CWE-94
DiscoveredCVEDescriptionWebsites
Jan, 2024CVE-2023-6528 Slider Revolution < 6.6.19 - Author+ Insecure Deserialization leading to RCE1,019,850
Jun, 2023CVE-2023-2359 Revolution Slider <= 6.6.12 - Author+ Remote Code Execution931,825
Feb, 2025CVE-2024-13346 Avada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode Execution114,078
Dec, 2025CVE-2025-13642 ProfilePress <= 4.16.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution49,753
Dec, 2024CVE-2024-12238 Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution46,655
Jul, 2024CVE-2024-37934 WordPress Ninja Forms plugin <= 3.8.4 - Subscriber+ Arbitrary Shortcode Execution vulnerability39,439
Jul, 2025CVE-2025-6744 Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution38,887
Jan, 2025CVE-2024-11733 WordPress Popular Posts <= 7.1.0 - Unauthenticated Arbitrary Shortcode Execution36,585
Dec, 2023CVE-2023-49830 WordPress Astra Pro Plugin <= 4.3.1 is vulnerable to Remote Code Execution (RCE)34,910
Feb, 2025CVE-2024-13345 Avada Builder <= 3.11.13 - Unauthenticated Arbitrary Shortcode Execution34,418

Websites affected by CWE-94

Top websites that are affected by CWE-94. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States***
****.com United States***
********.****.com United States***
***.*********.com Singapore*,***
*****.pl Poland*,***
*************.**.za South Africa*,***
******.com United States*,***
***.int Switzerland*,***
*****.com United States*,***
**********.org United States*,***
See full domain list