CWE-116— Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.— MITRE CWE catalog
574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-116page 6 of 12
- CVE-2026-73195HIGHCVSS 7.3EG 7.32026-09-14
Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes. When such users are included in a CSV export and the generated CS…
- CVE-2026-45011HIGHCVSS 7.3EG 7.32026-05-14
ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vulnerability in the image widget functionality. A user with the Editor role can configure an image widget link to use a ja…
- CVE-2026-43939HIGHCVSS 7.3EG 7.32026-05-12
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread pag…
- CVE-2026-23880HIGHCVSS 7.3EG 7.32026-01-19
OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f have a stored cross-site s…
- CVE-2025-27109HIGHCVSS 7.3EG 7.32025-02-21
solid-js is a declarative, efficient, and flexible JavaScript library for building user interfaces. In affected versions Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HT…
- CVE-2025-27108HIGHCVSS 7.3EG 7.32025-02-21
dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. In affected versions the use of javascript's `.replace()` opens up to potential Cross-site Scripting (XSS) vulnerabilities with the special replacement patterns beginn…
- CVE-2026-107823HIGHCVSS 7.2EG 7.22026-10-09
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the MariaDB view FRM parser did not safely encode embedded newline characters in a username. An account…
- CVE-2026-44913HIGHCVSS 7.2EG 7.22026-06-22
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowe…
- CVE-2026-40871HIGHCVSS 7.2EG 7.22026-04-21
mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category field via the Mailcow API. The /api/v1/add/mailbox endpoint …
- CVE-2026-25932HIGHCVSS 7.2EG 7.22026-04-06
GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.
- CVE-2025-15312HIGHCVSS 7.2EG 7.22026-02-05
Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.
- CVE-2025-68460HIGHCVSS 7.2EG 7.22025-12-18
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
- CVE-2025-60787HIGHCVSS 7.2EG 7.22025-10-03
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin a…
- CVE-2025-46340HIGHCVSS 7.2EG 7.22025-05-05
Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker…
- CVE-2023-3668HIGHCVSS 7.2EG 7.22023-07-14
Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.
- CVE-2023-36921HIGHCVSS 7.2EG 7.22023-07-11
SAP Solution Manager (Diagnostics agent) - version 7.20, allows an attacker to tamper with headers in a client request. This misleads SAP Diagnostics Agent to serve poisoned content to the server. On successful exploitation, the attacker c…
- CVE-2023-28733HIGHCVSS 7.2EG 7.22023-03-30
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects A…
- CVE-2021-29854HIGHCVSS 7.2EG 7.22022-05-03
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerabi…
- CVE-2020-26116HIGHCVSS 7.2EG 7.22020-09-27
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in t…
- CVE-2018-8920HIGHCVSS 7.2EG 7.22018-12-24
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV forma…
- CVE-2026-48209HIGHCVSS 7.1EG 7.12026-06-01
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via crafted request parameters associated wi…
- CVE-2025-61084HIGHCVSS 7.1EG 7.12025-11-05
MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An attacker can craft a From: header with multiple invisible Unicode thin spaces to display a spoof…
- CVE-2025-48062HIGHCVSS 7.1EG 7.12025-06-09
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, certain invites via email may result in HTM…
- CVE-2025-24338HIGHCVSS 7.1EG 7.12025-04-30
A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to execute arbitrary client-side code in the context of another user's browser via multip…
- CVE-2026-53693MEDIUMCVSS 6.9EG 6.92026-06-10
A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, …
- CVE-2025-32078MEDIUMCVSS 6.9EG 6.92025-04-11
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Version Compare Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Version Compare Extension: from 1.39 through 1.43.
- CVE-2025-32072MEDIUMCVSS 6.9EG 6.92025-04-11
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows WebView Injection.This issue affects Mediawiki Core - Feed Utils: from 1.39 through 1.43.
- CVE-2022-23620MEDIUMCVSS 6.8EG 6.82022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions AbstractSxExportURLFactoryActionHandler#processSx does not escape anything from SSX document references when seri…
- CVE-2020-26283MEDIUMCVSS 6.8EG 6.82021-03-24
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in hiding input from th…
- CVE-2019-6109MEDIUMCVSS 6.8EG 6.82019-01-31
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI cont…
- CVE-2026-55855MEDIUMCVSS 6.5EG 6.52026-08-28
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer paramet…
- CVE-2026-55618MEDIUMCVSS 6.5EG 6.52026-08-25
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, the clean_found_uri function in eml_parser/parser.py validates potential URL …
- CVE-2026-54364MEDIUMCVSS 6.5EG 6.52026-07-30
CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to …
- CVE-2026-50659MEDIUMCVSS 6.5EG 6.52026-07-14
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
- CVE-2026-9354MEDIUMCVSS 6.5EG 6.52026-05-24
A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost Agent. The manipulation of the argument format_message results in escaping of ou…
- CVE-2026-31898MEDIUMCVSS 6.5EG 6.52026-03-18
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pas…
- CVE-2026-24439MEDIUMCVSS 6.5EG 6.52026-01-26
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrect…
- CVE-2025-6429MEDIUMCVSS 6.5EG 6.52025-06-24
Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to …
- CVE-2025-5271MEDIUMCVSS 6.5EG 6.52025-05-27
Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 139 and Thunderbird 139.
- CVE-2024-47224MEDIUMCVSS 6.5EG 6.52024-10-21
A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a CRLF injection attack due to inadequate encoding of user input …
- CVE-2023-45359MEDIUMCVSS 6.5EG 6.52024-10-09
An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can have markup.
- CVE-2024-45808MEDIUMCVSS 6.5EG 6.52024-09-20
Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This is achieved by exploiting the lack of vali…
- CVE-2024-45299MEDIUMCVSS 6.5EG 6.52024-09-06
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctly, the administrator / event admin could break their own in…
- CVE-2024-39736MEDIUMCVSS 6.5EG 6.52024-07-15
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable …
- CVE-2024-29156MEDIUMCVSS 6.5EG 6.52024-03-18
In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account informat…
- CVE-2023-40453MEDIUMCVSS 6.5EG 6.52023-11-07
Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might …
- CVE-2023-5654MEDIUMCVSS 6.5EG 6.52023-10-19
The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requ…
- CVE-2023-23599MEDIUMCVSS 6.5EG 6.52023-06-02
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102…
- CVE-2021-45226MEDIUMCVSS 6.5EG 6.52022-01-24
An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, attackers can cause it to send password-reset e-mails pointing to arbitrary websites.
- CVE-2021-4068MEDIUMCVSS 6.5EG 6.52021-12-23
Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Map vulnerabilities like CWE-116 to your infrastructure
EchelonGraph correlates every CVE — across CWE-116 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →