CWE-627: Dynamic Variable Evaluation
In a language where the user can influence the name of a variable at runtime, if the variable names are not controlled, an attacker can read or write to arbitrary variables, or access arbitrary functions.
5 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-2452 — Unsafe variable evaluation in email templates
- CVE-2026-2451 — Unsafe variable evaluation in email templates
- CVE-2026-2415 — Unsafe variable evaluation in email templates
Recently published
- CVE-2026-2452 — Unsafe variable evaluation in email templates
- CVE-2026-2451 — Unsafe variable evaluation in email templates
- CVE-2026-2415 — Unsafe variable evaluation in email templates