CWE-116— Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.— MITRE CWE catalog
574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-116page 11 of 12
- CVE-2024-47528MEDIUMCVSS 4.8EG 4.82024-10-01
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be achieved by uploading a new Background for a Custom Map. Users with "admin" role can set background for a custom map, this…
- CVE-2023-6005MEDIUMCVSS 4.8EG 4.82024-01-16
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even wh…
- CVE-2022-2099MEDIUMCVSS 4.8EG 4.82022-07-17
The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles
- CVE-2022-0210MEDIUMCVSS 4.8EG 4.82022-01-18
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to…
- CVE-2026-106444MEDIUMCVSS 4.7EG 4.72026-10-06
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.precompile() uses quotedString() in lib/handlebars/compiler/code-gen.js to emit static template text into generated JavaScri…
- CVE-2024-50349MEDIUMCVSS 4.7EG 4.72025-01-14
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using …
- CVE-2026-77353MEDIUMCVSS 4.6EG 4.62026-08-31
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequen…
- CVE-2026-66486MEDIUMCVSS 4.6EG 4.62026-08-10
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker …
- CVE-2026-33657MEDIUMCVSS 4.6EG 4.62026-04-13
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrar…
- CVE-2024-47531MEDIUMCVSS 4.6EG 4.62024-09-30
Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected insid…
- CVE-2023-3190MEDIUMCVSS 4.6EG 4.62023-06-10
Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
- CVE-2021-32812MEDIUMCVSS 4.6EG 4.62021-08-02
Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cross-site scripting vulnerability in frontend HTTP server. The…
- CVE-2026-47562MEDIUMCVSS 4.4EG 4.42026-09-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could inject crafted text into the kernel log because the supplied version string is not properly sanitized. A successful exploit of this vu…
- CVE-2025-12697MEDIUMCVSS 4.4EG 4.42026-03-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API …
- CVE-2026-87550MEDIUMCVSS 4.3EG 4.32026-09-09
Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-84655MEDIUMCVSS 4.3EG 4.32026-09-02
Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Py…
- CVE-2026-44458MEDIUMCVSS 4.3EG 4.32026-05-13
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property na…
- CVE-2026-0818MEDIUMCVSS 4.3EG 4.32026-01-28
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled with HTML and CSS, then the decrypted contents were rendered in a context in wh…
- CVE-2026-22712MEDIUMCVSS 4.3EG 4.32026-01-09
Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input Data Manipulation.This issue affects Mediawiki - ApprovedRe…
- CVE-2025-0607MEDIUMCVSS 4.3EG 4.32025-10-06
Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affects Logo Cloud: before 2.57.
- CVE-2025-3942MEDIUMCVSS 4.3EG 4.32025-05-22
Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: bef…
- CVE-2024-21499MEDIUMCVSS 4.3EG 4.32024-02-17
All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of secur…
- CVE-2022-2619MEDIUMCVSS 4.3EG 4.32022-08-12
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML pa…
- CVE-2021-23266MEDIUMCVSS 4.3EG 4.32022-05-16
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
- CVE-2020-27958MEDIUMCVSS 4.3EG 4.32022-02-26
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.
- CVE-2022-0124MEDIUMCVSS 4.3EG 4.32022-01-18
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are s…
- CVE-2021-38751MEDIUMCVSS 4.3EG 4.32021-08-16
A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM.
- CVE-2021-30589MEDIUMCVSS 4.3EG 4.32021-08-03
Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.
- CVE-2020-4282MEDIUMCVSS 4.3EG 4.32020-04-08
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow an authenticated user to perform unauthorized actions by bypassing illegal character restrictions. X-Force ID: 176205.
- CVE-2019-11268MEDIUMCVSS 4.3EG 4.32019-07-11
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones …
- CVE-2026-52846MEDIUMCVSS 4.2EG 4.22026-06-16
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>,…
- CVE-2025-23377MEDIUMCVSS 4.2EG 4.22025-04-28
Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to inject arbi…
- CVE-2017-12340MEDIUMCVSS 4.2EG 4.22017-11-30
A vulnerability in Cisco NX-OS System Software running on Cisco MDS Multilayer Director Switches, Cisco Nexus 7000 Series Switches, and Cisco Nexus 7700 Series Switches could allow an authenticated, local attacker to access the Bash shell …
- CVE-2026-63466MEDIUMCVSS 4.1EG 4.12026-08-21
Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path template…
- CVE-2023-2200MEDIUMCVSS 4.1EG 4.12023-07-13
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML i…
- CVE-2025-0083MEDIUMCVSS 4.0EG 4.02025-08-26
In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not neede…
- CVE-2023-28362MEDIUMCVSS 4.0EG 4.02025-01-09
The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value. This results in the potential for downstream services which enforce RFC compliance on HTTP response headers to remove…
- CVE-2023-1711MEDIUMCVSS 4.0EG 4.02023-05-30
A vulnerability exists in a FOXMAN-UN and UNEM logging component, it only affects systems that use remote authentication to the network elements. If exploited an attacker could obtain confidential information. List of CPEs: * cpe:2.…
- CVE-2026-40011LOWCVSS 3.7EG 3.72026-06-25
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected …
- CVE-2026-48598LOWCVSS 3.7EG 3.72026-06-02
Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each dispos…
- CVE-2026-42040LOWCVSS 3.7EG 3.72026-04-24
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character mapping (charMap) at line 21 that reverses the safe percent-enc…
- CVE-2026-33597LOWCVSS 3.7EG 3.72026-04-22
PRSD detection denial of service
- CVE-2024-42332LOWCVSS 3.7EG 3.72024-11-27
The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines of information and have forged data show in the Zabbix UI. This attack requires SNMP auth to be off and/or …
- CVE-2020-7694LOWCVSS 3.7EG 3.72020-07-27
This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, the default behaviour of uvicorn is to log its details to eith…
- CVE-2026-45710LOWCVSS 3.5EG 3.52026-07-14
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=` ## Summary `WidgetVariante::renderVariantList` (`Core/Lib/Widget/WidgetVariante.…
- CVE-2025-12734LOWCVSS 3.5EG 3.52025-12-11
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs…
- CVE-2025-30345LOWCVSS 3.5EG 3.52025-03-21
An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most…
- CVE-2024-34355LOWCVSS 3.5EG 3.52024-05-14
TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript e…
- CVE-2021-32679LOWCVSS 3.5EG 3.52021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed …
- CVE-2020-29023LOWCVSS 3.5EG 3.52021-02-16
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet progr…
Map vulnerabilities like CWE-116 to your infrastructure
EchelonGraph correlates every CVE — across CWE-116 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →