The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
Volume of CVEs assigned to CWE-95 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
148 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33017CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building | Mar 20, 2026 | 9.8 | 99 | YES | YES |
CVE-2025-24893CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to | Feb 20, 2025 | 9.8 | 99 | YES | YES |
CVE-2024-36401CRITICAL GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow | Jul 1, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-7954CRITICAL The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can exe | Aug 23, 2024 | 9.8 | 89 | NO | YES |
CVE-2024-21650CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its use | Jan 8, 2024 | 9.8 | 83 | NO | YES |
CVE-2023-7101HIGH Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to | Dec 24, 2023 | 7.8 | 81 | YES | YES |
CVE-2024-36404CRITICAL GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application u | Jul 2, 2024 | 9.8 | 80 | NO | YES |
CVE-2023-37462HIGH XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an i | Jul 14, 2023 | 8.8 | 80 | NO | YES |
CVE-2023-46731CRITICAL XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the | Nov 6, 2023 | 9.8 | 78 | NO | NO |
CVE-2023-35150HIGH XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0 | Jun 23, 2023 | 8.0 | 70 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.