CWE-116— Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.— MITRE CWE catalog
574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-116page 1 of 12
- CVE-2022-42948CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-24
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
- CVE-2024-38475CRITICALCVSS 9.1EG 9.1⚠ KEV2024-07-01
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any U…
- CVE-2026-20245CRITICALCVSS 7.8EG 9.0⚠ KEV2026-06-04
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local…
- CVE-2022-24682CRITICALCVSS 6.1EG 9.0⚠ KEV2022-02-09
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside…
- CVE-2026-106102CRITICALCVSS 10.0EG 10.02026-10-06
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into ti…
- CVE-2025-55730CRITICALCVSS 10.0EG 10.02025-09-09
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the title in the confluence paste code macro allows remote…
- CVE-2025-55729CRITICALCVSS 10.0EG 10.02025-09-09
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the ac:type in the ConfluenceLayoutSection macro allows re…
- CVE-2023-47143CRITICALCVSS 10.0EG 10.02024-02-02
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks again…
- CVE-2025-8276CRITICALCVSS 9.8EG 10.02025-09-16
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulner…
- CVE-2026-42810CRITICALCVSS 9.9EG 9.92026-05-04
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `…
- CVE-2025-49013CRITICALCVSS 9.9EG 9.92025-06-09
WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user cont…
- CVE-2023-26472CRITICALCVSS 9.9EG 9.92023-03-02
XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new pag…
- CVE-2022-41934CRITICALCVSS 9.9EG 9.92022-11-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly accessible documents including the menu macro can execute arbitrary Groovy, Python or Velocity c…
- CVE-2022-36100CRITICALCVSS 9.9EG 9.92022-09-08
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tag…
- CVE-2022-36099CRITICALCVSS 9.9EG 9.92022-09-08
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax incl…
- CVE-2022-23603CRITICALCVSS 9.9EG 9.92022-02-01
iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is po…
- CVE-2026-13684CRITICALCVSS 9.8EG 9.82026-09-18
An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct d…
- CVE-2026-90999CRITICALCVSS 9.8EG 9.82026-09-16
Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can subm…
- CVE-2026-54133CRITICALCVSS 9.8EG 9.82026-06-12
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controll…
- CVE-2025-56266CRITICALCVSS 9.8EG 9.82025-09-08
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.
- CVE-2025-46347CRITICALCVSS 9.8EG 9.82025-04-29
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitr…
- CVE-2025-31651CRITICALCVSS 9.8EG 9.82025-04-28
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those r…
- CVE-2024-10441CRITICALCVSS 9.8EG 9.82025-03-19
Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allows remote att…
- CVE-2024-55663CRITICALCVSS 9.8EG 9.82024-12-12
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (reque…
- CVE-2024-38474CRITICALCVSS 9.8EG 9.82024-07-01
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts mea…
- CVE-2024-31866CRITICALCVSS 9.8EG 9.82024-04-09
Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: f…
- CVE-2023-38316CRITICALCVSS 9.8EG 9.82023-11-17
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenND…
- CVE-2023-48655CRITICALCVSS 9.8EG 9.82023-11-17
An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.
- CVE-2023-46301CRITICALCVSS 9.8EG 9.82023-10-22
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.
- CVE-2023-46300CRITICALCVSS 9.8EG 9.82023-10-22
iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.
- CVE-2023-24480CRITICALCVSS 9.8EG 9.82023-07-13
Controller DoS due to stack overflow when decoding a message from the server. See Honeywell Security Notification for recommendations on upgrading and versioning.
- CVE-2022-46387CRITICALCVSS 9.8EG 9.82023-03-28
ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.
- CVE-2021-42010CRITICALCVSS 9.8EG 9.82022-10-24
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.
- CVE-2022-41443CRITICALCVSS 9.8EG 9.82022-10-03
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
- CVE-2020-36599CRITICALCVSS 9.8EG 9.82022-08-18
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
- CVE-2022-35153CRITICALCVSS 9.8EG 9.82022-08-18
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
- CVE-2022-36446CRITICALCVSS 9.8EG 9.82022-07-25
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
- CVE-2022-28375CRITICALCVSS 9.8EG 9.82022-07-14
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metac…
- CVE-2022-29599CRITICALCVSS 9.8EG 9.82022-05-23
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
- CVE-2022-26174CRITICALCVSS 9.8EG 9.82022-03-21
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injected into the display fields.
- CVE-2022-25235CRITICALCVSS 9.8EG 9.82022-02-16
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
- CVE-2021-44042CRITICALCVSS 9.8EG 9.82021-12-14
An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected …
- CVE-2021-41132CRITICALCVSS 9.8EG 9.82021-10-14
OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, th…
- CVE-2021-28940CRITICALCVSS 9.8EG 9.82021-04-02
Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an issue on the /scripts/magpie_debug.php and /scripts/magpie_sim…
- CVE-2019-11325CRITICALCVSS 9.8EG 9.82019-11-21
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/v…
- CVE-2019-10074CRITICALCVSS 9.8EG 9.82019-09-11
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Enco…
- CVE-2018-15494CRITICALCVSS 9.8EG 9.82018-08-18
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
- CVE-2018-9246CRITICALCVSS 9.8EG 9.82018-06-08
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create()…
- CVE-2017-8303CRITICALCVSS 9.8EG 9.82017-05-05
An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.
- CVE-2022-34820CRITICALCVSS 8.4EG 9.82022-07-12
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC…
Map vulnerabilities like CWE-116 to your infrastructure
EchelonGraph correlates every CVE — across CWE-116 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →