Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2025-02-22 CVE-2025-1509 The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.
network
low complexity
CWE-94
7.3
2025-02-22 CVE-2025-1510 The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1.
network
low complexity
CWE-94
7.3
2025-02-21 CVE-2025-1548 A vulnerability was found in iteachyou Dreamer CMS 4.1.3.
network
low complexity
CWE-94
3.5
2025-02-21 CVE-2024-13900 Code Injection vulnerability in Satollo Head, Footer, and Post Injections
The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0.
network
low complexity
satollo CWE-94
7.2
2025-02-20 CVE-2024-13792 Code Injection vulnerability in Ex-Themes Woocommerce Food
The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2.
network
low complexity
ex-themes CWE-94
critical
9.8
2025-02-19 CVE-2025-1465 Code Injection vulnerability in Lmxcms 1.41
A vulnerability, which was classified as problematic, was found in lmxcms 1.41.
network
high complexity
lmxcms CWE-94
6.6
2025-02-18 CVE-2024-13689 The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6.
network
low complexity
CWE-94
6.3
2025-02-18 CVE-2024-13797 Code Injection vulnerability in Presslayouts Pressmart
The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16.
network
low complexity
presslayouts CWE-94
critical
9.8
2025-02-17 CVE-2025-1392 A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic.
network
low complexity
CWE-94
3.5
2025-02-16 CVE-2025-1360 A vulnerability, which was classified as problematic, was found in Internet Web Solutions Sublime CRM up to 20250207.
network
low complexity
CWE-94
3.5