Topic
Code Injection
11 reports tagged Code Injection, spanning vulnerability coverage.
Articles tagged Code Injection
-
VulnerabilityDrag and Drop Multiple File Upload for Contact Form 7 Code Injection (CVE-2026-18781)
CVE-2026-18781 is a CVSS 8.1 code injection in a Contact Form 7 WordPress add-on, reported exploited by VulnCheck alone.
-
VulnerabilityFlowise Code Injection (CVE-2026-69255)
CVE-2026-69255 is a CVSS 8.8 code injection flaw in Flowise letting authenticated attackers run OS commands as root, reported exploited by VulnCheck.
-
VulnerabilityGeoNetwork Code Injection (CVE-2026-58400)
CVE-2026-58400 is a CVSS 9.1 code injection flaw in GeoNetwork via unsecured XSLT processing, fixed in 4.4.12/4.2.17, reported exploited by VulnCheck.
-
VulnerabilityGitea Code Injection (CVE-2026-60004)
CVE-2026-60004 is a CVSS 9.8 code injection flaw in Gitea allowing RCE via the diffpatch API, confirmed exploited by both CISA and VulnCheck KEV.
-
VulnerabilityLangflow Code Injection (CVE-2026-0768)
CVE-2026-0768 is a CVSS 9.8 code injection flaw in Langflow allowing unauthenticated remote code execution as root, reported exploited by VulnCheck KEV.
-
VulnerabilitySPIP Code Injection (CVE-2026-77806)
CVE-2026-77806 is a CVSS 9.8 code injection flaw in the SPIP CMS allowing unauthenticated RCE, with NVD itself noting exploitation in the wild.
-
VulnerabilityThe Events Calendar Code Injection (CVE-2026-78159)
CVE-2026-78159 is a CVSS 9.8 code injection flaw enabling unauthenticated RCE in WordPress plugin The Events Calendar, reported exploited by VulnCheck KEV.
-
VulnerabilityWP Compress Code Injection (CVE-2026-73343)
CVE-2026-73343 is a CVSS 10.0 code injection flaw enabling unauthenticated RCE in WP Compress before 7.20.01, reported as exploited by VulnCheck's KEV catalog.
-
Vulnerability9 CVEs: CodeWhale & deepseek-tui (CVE-2026-75913)
Nine CodeWhale AI coding-agent CVEs: arbitrary file write, an SSRF bypass, two auto-approved RCE paths, and five more approval-gate and sandbox failures.
-
Vulnerability3 n8n CVEs (CVE-2025-68613)
A KEV-listed, CVSS 9.9 remote code execution flaw in n8n workflow expressions, plus two related sandbox-escape CVEs in the same legacy engine.
-
VulnerabilityN-able N-central Code Injection (CVE-2026-86218)
CVE-2026-86218 is a CVSS 9.8 static code injection in N-able N-central allowing pre-authentication remote code execution. CISA added it to KEV on Sept. 8, 2026.