CWE-116— Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.— MITRE CWE catalog
574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-116page 10 of 12
- CVE-2023-28952MEDIUMCVSS 5.3EG 5.32024-05-03
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.
- CVE-2024-27938MEDIUMCVSS 5.3EG 5.32024-03-11
Postal is an open source SMTP server. Postal versions less than 3.0.0 are vulnerable to SMTP Smuggling attacks which may allow incoming e-mails to be spoofed. This, in conjunction with a cooperative outgoing SMTP service, would allow for a…
- CVE-2023-7234MEDIUMCVSS 5.3EG 5.32024-01-16
OPCUAServerToolkit will write a log message once an OPC UA client has successfully connected containing the client's self-defined description field.
- CVE-2023-42183MEDIUMCVSS 5.3EG 5.32023-12-15
lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of intended access restrictions, such as when U+1FEF is converted to a backtick.
- CVE-2023-41889MEDIUMCVSS 5.3EG 5.32023-09-15
SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a logical validation or a security check is performed before a Unicode normalization. The U…
- CVE-2023-40014MEDIUMCVSS 5.3EG 5.32023-08-10
OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)…
- CVE-2023-34036MEDIUMCVSS 5.3EG 5.32023-07-17
Reactive web applications that use Spring HATEOAS to produce hypermedia-based responses might be exposed to malicious forwarded headers if they are not behind a trusted proxy that ensures correctness of such headers, or if they don't have…
- CVE-2023-36919MEDIUMCVSS 5.3EG 5.32023-07-11
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the Referrer-Policy response header is not implemented, allowing an unauthenticated attacker to obtain referrer details, res…
- CVE-2023-28487MEDIUMCVSS 5.3EG 5.32023-03-16
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
- CVE-2023-28486MEDIUMCVSS 5.3EG 5.32023-03-16
Sudo before 1.9.13 does not escape control characters in log messages.
- CVE-2023-0595MEDIUMCVSS 5.3EG 5.32023-02-24
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the misinterpretation of log files when malicious packets are sent to the Geo SCADA server's database web port (default 443). Affected products: EcoSt…
- CVE-2022-32549MEDIUMCVSS 5.3EG 5.32022-06-22
Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.
- CVE-2021-43410MEDIUMCVSS 5.3EG 5.32021-12-09
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 …
- CVE-2021-39367MEDIUMCVSS 5.3EG 5.32021-08-23
Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.
- CVE-2021-20333MEDIUMCVSS 5.3EG 5.32021-07-23
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior…
- CVE-2020-36173MEDIUMCVSS 5.3EG 5.32021-01-06
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
- CVE-2020-28954MEDIUMCVSS 5.3EG 5.32020-11-19
web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.
- CVE-2020-24592MEDIUMCVSS 5.3EG 5.32020-09-25
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.
- CVE-2020-6261MEDIUMCVSS 5.3EG 5.32020-07-01
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.
- CVE-2018-20586MEDIUMCVSS 5.3EG 5.32020-03-12
bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.
- CVE-2019-19714MEDIUMCVSS 5.3EG 5.32019-12-17
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
- CVE-2019-15944MEDIUMCVSS 5.3EG 5.32019-09-05
In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.
- CVE-2019-11717MEDIUMCVSS 5.3EG 5.32019-07-23
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Fi…
- CVE-2019-3571MEDIUMCVSS 5.3EG 5.32019-07-16
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.
- CVE-2022-34316MEDIUMCVSS 3.7EG 5.32022-11-14
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452.
- CVE-2026-65085MEDIUMCVSS 5.2EG 5.22026-08-25
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data …
- CVE-2026-63208MEDIUMCVSS 5.1EG 5.12026-09-25
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide this…
- CVE-2026-88921MEDIUMCVSS 5.1EG 5.12026-09-10
MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the conve…
- CVE-2026-73161MEDIUMCVSS 5.1EG 5.12026-08-11
Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function previously returned the underlying text directly when no search query was supplied, or pe…
- CVE-2026-58487MEDIUMCVSS 5.1EG 5.12026-07-13
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe handling of the local-part of registered email addresses, HedgeDoc was vulnerable to stored HTML Injection through its…
- CVE-2025-34141MEDIUMCVSS 5.1EG 5.12025-07-22
A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverterServlet` component. This vulnerability requires user interaction, such as clicking a crafted link, and may result in e…
- CVE-2026-73479MEDIUMCVSS 5.0EG 5.02026-08-13
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequences that are interpreted by the terminal emulator when printe…
- CVE-2026-73480MEDIUMCVSS 5.0EG 5.02026-08-13
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing escape sequences that are interpreted by the terminal, enabling…
- CVE-2026-44972MEDIUMCVSS 5.0EG 5.02026-05-27
GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-readable output without escaping terminal co…
- CVE-2024-0690MEDIUMCVSS 5.0EG 5.02024-02-06
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the tas…
- CVE-2023-28101MEDIUMCVSS 5.0EG 5.02023-03-16
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8, 1.12.8, 1.14.4, and 1.15.4, if an attacker publishes a Flatpak app with elevated permissions, they can hide t…
- CVE-2021-39027MEDIUMCVSS 5.0EG 5.02022-05-06
IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of t…
- CVE-2021-34630MEDIUMCVSS 5.0EG 5.02021-07-30
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers…
- CVE-2026-63329MEDIUMCVSS 4.9EG 4.92026-09-21
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the…
- CVE-2025-25029MEDIUMCVSS 4.9EG 4.92025-05-28
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
- CVE-2024-22356MEDIUMCVSS 4.9EG 4.92024-03-26
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or trace files that could be read by a privileged user. …
- CVE-2023-5968MEDIUMCVSS 4.9EG 4.92023-11-06
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
- CVE-2021-40694MEDIUMCVSS 4.9EG 4.92022-09-29
Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.
- CVE-2026-104907MEDIUMCVSS 4.8EG 4.82026-10-02
MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders tag identifiers inside an inline JavaScript onclick attribute. The tag I…
- CVE-2026-95659MEDIUMCVSS 4.8EG 4.82026-09-22
MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-themed …
- CVE-2026-61399MEDIUMCVSS 4.8EG 4.82026-08-21
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recom…
- CVE-2026-73055MEDIUMCVSS 4.8EG 4.82026-08-15
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape a…
- CVE-2026-50642MEDIUMCVSS 4.8EG 4.82026-07-29
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application only strips ANSI SGR sequences while allowing other control characters, including carriage return (\r) and escap…
- CVE-2026-34246MEDIUMCVSS 4.8EG 4.82026-05-19
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In app/Http/Controllers/Admin/RoleController…
- CVE-2026-40593MEDIUMCVSS 4.8EG 4.82026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator c…
Map vulnerabilities like CWE-116 to your infrastructure
EchelonGraph correlates every CVE — across CWE-116 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →