CWE-96: Static Code Injection
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before inserting the input into an executable resource, such as a library, configuration file, or template.
22 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allo
- CVE-2024-43400 — XWiki Platform allows XSS through XClass name in string properties
- CVE-2025-36595 — Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically
- CVE-2024-0788 — SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulation
- CVE-2024-37900 — XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
- CVE-2025-7825 — Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation
- CVE-2025-57707 — File Station 5
- CVE-2024-13268 — Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032
- CVE-2024-13267 — Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
- CVE-2024-13265 — Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029
- CVE-2024-13264 — Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028
- CVE-2024-13263 — Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027
Recently published
- CVE-2026-86218 — pre-authentication remote code execution
- CVE-2025-57707 — File Station 5
- CVE-2025-7825 — Schema Plugin For Divi, Gutenberg & Shortcodes <= 4.3.2 - Authenticated (Contributor+) Object Instantiation
- CVE-2025-36595 — Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically
- CVE-2025-30091 — In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allo
- CVE-2024-13268 — Opigno - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-032
- CVE-2024-13267 — Opigno TinCan Question Type - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-031
- CVE-2024-13265 — Opigno Learning path - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-029
- CVE-2024-13264 — Opigno module - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-028
- CVE-2024-13263 — Opigno group manager - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-027
- CVE-2024-43400 — XWiki Platform allows XSS through XClass name in string properties
- CVE-2024-37900 — XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
- CVE-2024-0788 — SUPERAntiSpyware Pro X v10.0.1260 - Kernel-level API parameters manipulation
More specific weaknesses
- CWE-97 — Improper Neutralization of Server-Side Includes (SSI) Within a Web Page