Cyber Posture

CWE · MITRE source

CWE-96Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

Abstraction: Base · CVEs in our corpus: 23

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before inserting the input into an executable resource, such as a library, configuration file, or template.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SC-34Non-modifiable Executable ProgramsSCEliminates the possibility of static code injection into saved executables by making the storage non-modifiable.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-558774.09.90.33392024-12-12
CVE-2021-391153.07.20.25742021-09-01
CVE-2024-556622.79.90.12772024-12-12
CVE-2020-61432.69.80.10782020-09-01
CVE-2020-61442.69.80.10782020-09-01
CVE-2023-397262.19.80.01592023-10-26
CVE-2024-434002.19.00.05692024-08-19
CVE-2015-20792.19.90.02782025-04-28
CVE-2022-08952.09.80.01202022-03-10
CVE-2022-439382.08.80.04542023-04-03
CVE-2024-132642.09.80.00222025-01-09
CVE-2025-577071.88.80.00072026-02-11
CVE-2024-324871.78.60.00332024-04-13
CVE-2024-379001.66.40.05332024-07-31
CVE-2024-132651.57.50.00142025-01-09
CVE-2024-132671.57.50.00142025-01-09
CVE-2025-365951.57.20.00692025-06-27
CVE-2024-132681.46.80.00122025-01-09
CVE-2022-39601.36.30.00632023-04-03
CVE-2024-07881.36.60.00042024-01-29
CVE-2025-78251.36.30.00102025-10-03
CVE-2024-132631.15.50.00092025-01-09
CVE-2025-300910.10.00.01402025-03-25