Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-470'

View all threats tagged with 'cwe-470'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-470

Threats Tagged 'cwe-470'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-13051: CWE-1336 Improper Neutralization of Special Elements Used in a Template EngineCVE-2026-13051
0

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template. validate runs HTML::Tidy over the submitted markup and passes each resulting message to add_error as its first argument, which add_error hands to the language handle as the Locale::Maketext message key. The default handle's lexicon sets `_AUTO`, so a message that is not a lexicon entry is compiled as a bracket notation template instead of being looked up. Tidy diagnostics quote the offending attribute name or value, so a bracket group in the submitted markup reaches the template position, where the first token of the group names a method called on the language handle and the remaining tokens are its arguments. A group such as `[0]` makes the compile croak, and neither the field nor the handle catches it, so the exception leaves validate. `[sprintf,%2000000000d,7]` reaches CORE::sprintf with an attacker chosen field width. One submission of crafted markup to an HtmlArea field throws an unhandled exception out of form validation or allocates an arbitrary amount of memory, and an application whose language handle subclass defines side effecting public methods makes those callable with attacker chosen arguments. The other field types pass fixed templates with the submitted value in an argument slot, where it stays inert, and are unaffected.

Join the discussion
CVE-2026-19135: CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection') in The OpenNMS Group MeridianCVE-2026-19135
0

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

Join the discussion
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. (CVE-2026-44416)CVE-2026-44416
0

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

Join the discussion
CVE-2026-44416: CWE-94 Improper Control of Generation of Code ('Code Injection') in Apache Software Foundation Apache RangerCVE-2026-44416
0

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

Join the discussion
CVE-2026-17593: CWE-470 Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection) in Sonatype Nexus RepositoryCVE-2026-17593
0

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout that was not visible through the administrative UI.

Join the discussion
CVE-2026-64663: CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in statamic cmsCVE-2026-64663
0

Statamic CMS versions prior to 5.74.1 and 6.24.0 contain a vulnerability where user-supplied input incorporated into Antlers templates can lead to unsafe reflection. This flaw allows unauthenticated attackers to manipulate templates, potentially causing loss of content and assets. The vulnerability is fixed in versions 5.74.1 and 6.24.0.

Join the discussion
CVE-2026-8400: CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in IBM WebSphere Application ServerCVE-2026-8400
0

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes.

Join the discussion
CVE-2026-6020: CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in devitemsllc ShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginCVE-2026-6020
0

The ShopLentor WordPress plugin up to version 3.3.7 contains a vulnerability that allows authenticated administrators to execute arbitrary PHP functions via a REST API endpoint. This occurs because user input is passed directly to call_user_func() without validation or an allowlist, enabling unsafe reflection.

Join the discussion
CVE-2026-61536: CWE-94: Improper Control of Generation of Code ('Code Injection') in masci banksCVE-2026-61536
0

CVE-2026-61536 is a high-severity code injection vulnerability in the masci banks product prior to version 2.4.3. It arises from unsafe dynamic import and attribute access of Python callables based on attacker-controlled input in Tool JSON objects within LLM prompt templates. This allows arbitrary code execution in the hosting process. The issue was fixed in version 2.4.3.

Join the discussion
CVE-2026-53666: CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in remix-run react-routerCVE-2026-53666
0

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Tag: cwe-470
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses