CWE-116— Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.— MITRE CWE catalog
574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-116page 3 of 12
- CVE-2018-9433HIGHCVSS 8.8EG 8.82024-11-19
In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploi…
- CVE-2024-45498HIGHCVSS 8.8EG 8.82024-09-07
Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the …
- CVE-2023-29543HIGHCVSS 8.8EG 8.82023-06-02
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 11…
- CVE-2023-29541HIGHCVSS 8.8EG 8.82023-06-02
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating system…
- CVE-2022-28284HIGHCVSS 8.8EG 8.82022-12-22
SVG's <code><use></code> element could have been used to load unexpected content that could have executed script in certain circumstances. While the specification seems to allow this, other browsers do not, and web developers relied …
- CVE-2022-22744HIGHCVSS 8.8EG 8.82022-12-22
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windo…
- CVE-2022-28374HIGHCVSS 8.8EG 8.82022-07-14
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An authenticated remote attacker on the local network can inje…
- CVE-2022-28960HIGHCVSS 8.8EG 8.82022-05-19
A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.
- CVE-2022-0935HIGHCVSS 8.8EG 8.82022-04-07
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
- CVE-2021-38182HIGHCVSS 8.8EG 8.82021-12-14
Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privileges which can completely compromise the cluster.
- CVE-2020-24849HIGHCVSS 8.8EG 8.82020-11-05
A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remote code execution b…
- CVE-2020-24972HIGHCVSS 8.8EG 8.82020-08-29
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath comman…
- CVE-2020-10235HIGHCVSS 8.8EG 8.82020-03-09
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExi…
- CVE-2013-2011HIGHCVSS 8.8EG 8.82019-12-26
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
- CVE-2019-12675HIGHCVSS 8.8EG 8.82019-10-02
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges i…
- CVE-2019-12463HIGHCVSS 8.8EG 8.82019-09-09
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input…
- CVE-2018-8609HIGHCVSS 8.8EG 8.82018-11-14
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remo…
- CVE-2014-9938HIGHCVSS 8.8EG 8.82017-03-20
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1 variable, allowing a malicious repository to cause code execution.
- CVE-2022-23079HIGHEG 8.82022-06-22
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
- CVE-2026-77404HIGHCVSS 8.7EG 8.72026-09-16
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string instead of encoding them as URL query parameters wit…
- CVE-2026-55730HIGHCVSS 8.7EG 8.72026-07-24
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privi…
- CVE-2026-12496HIGHCVSS 8.7EG 8.72026-07-24
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary…
- CVE-2026-35569HIGHCVSS 8.7EG 8.72026-04-15
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controlled input is rendere…
- CVE-2025-8405HIGHCVSS 7.7EG 8.72025-12-11
GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of ot…
- CVE-2026-73417HIGHCVSS 8.6EG 8.62026-07-22
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an over…
- CVE-2026-59833HIGHCVSS 8.6EG 8.62026-07-09
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check f…
- CVE-2025-11085HIGHCVSS 8.6EG 8.62025-11-11
A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of malicious JavaScript, allowing for account takeover, credential theft, or redirection to a malicious …
- CVE-2023-4571HIGHCVSS 8.6EG 8.62023-08-30
In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Institute (ANSI) escape codes into Splunk ITSI log files that, when a vulnerable terminal app…
- CVE-2022-36392HIGHCVSS 8.6EG 8.62023-08-11
Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45, and 16.1.27 in Intel (R) CSME may allow an unauthenticated user to pote…
- CVE-2023-3997HIGHCVSS 8.6EG 8.62023-07-31
Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to c…
- CVE-2023-35941HIGHCVSS 8.6EG 8.62023-07-25
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12, a malicious client is able to construct credentials with permanent validity in some spec…
- CVE-2023-32712HIGHCVSS 8.6EG 8.62023-06-01
In Splunk Enterprise versions below 9.1.0.2, 9.0.5.1, and 8.2.11.2, an attacker can inject American National Standards Institute (ANSI) escape codes into Splunk log files that, when a vulnerable terminal application reads them, can potenti…
- CVE-2026-55214HIGHCVSS 8.5EG 8.52026-09-25
GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cr…
- CVE-2026-40568HIGHCVSS 8.5EG 8.52026-04-21
FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature. The sanitization function `Helper::stripDangerousTags()` (`app…
- CVE-2024-45219HIGHCVSS 8.5EG 8.52024-10-16
Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and volumes for attaching them as data disks to their existing instances. Due to missing validation checks for KVM-compatibl…
- CVE-2026-105801HIGHCVSS 8.4EG 8.42026-10-06
openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Pyth…
- CVE-2026-82409HIGHCVSS 8.4EG 8.42026-09-23
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request with…
- CVE-2026-42321HIGHCVSS 8.4EG 8.42026-06-03
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or 11.0.7 to receive a patch.
- CVE-2025-1308HIGHCVSS 8.4EG 8.42025-05-19
A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions.
- CVE-2024-45271HIGHCVSS 8.4EG 8.42024-10-15
An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.
- CVE-2021-28662HIGHCVSS 6.5EG 8.42021-05-27
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.
- CVE-2026-106107HIGHCVSS 8.3EG 8.32026-10-06
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 3.3.0, several @quasar/app-vite SSR and SSG rendering paths interpolated ssrContext.nonce directly into quoted HTML attributes. An application t…
- CVE-2026-95274HIGHCVSS 8.3EG 8.32026-09-29
Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium se…
- CVE-2025-55903HIGHCVSS 8.3EG 8.32025-10-10
A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, arbitrary HTML can be injected and rendered unescaped in clien…
- CVE-2024-10006HIGHCVSS 8.3EG 8.32024-10-30
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
- CVE-2023-39527HIGHCVSS 8.3EG 8.32023-08-07
PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to cross-site scripting through the `isCleanHTML` method. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are n…
- CVE-2026-61824HIGHCVSS 8.2EG 8.22026-08-21
Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse()…
- CVE-2026-33941HIGHCVSS 8.2EG 8.22026-03-27
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings — template file…
- CVE-2024-47845HIGHCVSS 8.2EG 8.22024-10-05
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: from 1.39.X before 1.39.9, from 1.41.X before 1.41.3, from 1.42…
- CVE-2023-45539HIGHCVSS 8.2EG 8.22023-11-28
HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to …
Map vulnerabilities like CWE-116 to your infrastructure
EchelonGraph correlates every CVE — across CWE-116 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →