CWE-116— Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.— MITRE CWE catalog
574 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-116page 9 of 12
- CVE-2026-44429MEDIUMCVSS 5.4EG 5.42026-05-14
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site s…
- CVE-2026-41318MEDIUMCVSS 5.4EG 5.42026-04-24
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's in-chat markdown renderer has an unsafe custom rule for images that interpol…
- CVE-2026-40483MEDIUMCVSS 5.4EG 5.42026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes without escaping via htmlspecialchars(). An authenticated user wi…
- CVE-2026-35208MEDIUMCVSS 5.4EG 5.42026-04-06
lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML into /streamer and the homepage “Live streams” widget by placing markup in their Twitch/YouTube stream title. CSP is …
- CVE-2026-33628MEDIUMCVSS 5.4EG 5.42026-03-26
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja v5.13.0 bypass the XSS denylist filter, allowing stored XSS payloads to execute when invo…
- CVE-2026-27016MEDIUMCVSS 5.4EG 5.42026-02-20
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization w…
- CVE-2026-26953MEDIUMCVSS 5.4EG 5.42026-02-19
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions table located on the A…
- CVE-2026-26952MEDIUMCVSS 5.4EG 5.42026-02-19
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through the local DNS records configuration page,…
- CVE-2026-25230MEDIUMCVSS 5.4EG 5.42026-02-09
FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain endpoints or link elements that redirec…
- CVE-2026-23630MEDIUMCVSS 5.4EG 5.42026-01-21
Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code block rendering is vulnerable to stored Cross-Site Scripting (XSS). The frontend can render attacker-controlled Mermaid di…
- CVE-2025-42896MEDIUMCVSS 5.4EG 5.42025-12-09
SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error message. This can cause the server to fetch attacker-supplied URL…
- CVE-2025-57880MEDIUMCVSS 5.4EG 5.42025-09-19
Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.
- CVE-2021-25262MEDIUMCVSS 5.4EG 5.42025-05-21
Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.
- CVE-2025-32074MEDIUMCVSS 5.4EG 5.42025-04-11
Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Confirm Account Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Confirm Account Extension: from 1.39 through 1.43.
- CVE-2023-35894MEDIUMCVSS 5.4EG 5.42025-03-07
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cro…
- CVE-2024-52891MEDIUMCVSS 5.4EG 5.42025-01-07
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.
- CVE-2024-9427MEDIUMCVSS 5.4EG 5.42024-12-24
A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koj…
- CVE-2023-26289MEDIUMCVSS 5.4EG 5.42024-07-30
IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site …
- CVE-2024-29894MEDIUMCVSS 5.4EG 5.42024-05-14
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` fro…
- CVE-2022-22399MEDIUMCVSS 5.4EG 5.42024-03-05
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-s…
- CVE-2023-3552MEDIUMCVSS 5.4EG 5.42023-07-08
Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
- CVE-2022-43543MEDIUMCVSS 5.4EG 5.42022-12-21
KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, an…
- CVE-2021-38997MEDIUMCVSS 5.4EG 5.42022-12-12
IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker…
- CVE-2022-30966MEDIUMCVSS 5.4EG 5.42022-05-17
Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attac…
- CVE-2022-0450MEDIUMCVSS 5.4EG 5.42022-03-28
The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber c…
- CVE-2021-29872MEDIUMCVSS 5.4EG 5.42022-01-18
IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote…
- CVE-2019-10362MEDIUMCVSS 5.4EG 5.42019-07-31
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain…
- CVE-2024-50629MEDIUMCVSS 5.3EG 5.42025-03-19
Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1-65374 and Synology DiskStation Manager (DSM) before 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 allow …
- CVE-2023-37875MEDIUMCVSS 3.0EG 5.42023-09-12
Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0.
- CVE-2026-105244MEDIUMCVSS 5.3EG 5.32026-10-06
Improper Encoding or Escaping of Output vulnerability in the RemoteSyslogAppender of Apache log4net. Every character outside visible ASCII and space was removed from the record instead of being escaped, so non-ASCII text and control chara…
- CVE-2026-94545MEDIUMCVSS 5.3EG 5.32026-09-30
Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be i…
- CVE-2026-13635MEDIUMCVSS 5.3EG 5.32026-09-18
An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information.
- CVE-2026-19641MEDIUMCVSS 5.3EG 5.32026-09-15
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, r…
- CVE-2026-79964MEDIUMCVSS 5.3EG 5.32026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability. An unauthenticated attacker with remote…
- CVE-2026-79952MEDIUMCVSS 5.3EG 5.32026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Encoding or Escaping of Output vulnerability. An unauthenticated attacker with remote access could potentia…
- CVE-2026-54287MEDIUMCVSS 5.3EG 5.32026-06-16
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated…
- CVE-2026-28898MEDIUMCVSS 5.3EG 5.32026-06-12
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :a…
- CVE-2026-49472MEDIUMCVSS 5.3EG 5.32026-06-09
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerabl…
- CVE-2026-2404MEDIUMCVSS 5.3EG 5.32026-04-14
CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload.
- CVE-2026-40023MEDIUMCVSS 5.3EG 5.32026-04-10
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions before 1.7.0, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets…
- CVE-2026-40021MEDIUMCVSS 5.3EG 5.32026-04-10
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3…
- CVE-2025-46583MEDIUMCVSS 5.3EG 5.32025-10-27
There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack.
- CVE-2025-61912MEDIUMCVSS 5.3EG 5.32025-10-10
python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash followed by a literal NUL byte instead of the RFC-4…
- CVE-2021-25254MEDIUMCVSS 5.3EG 5.32025-05-21
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
- CVE-2025-30657MEDIUMCVSS 5.3EG 5.32025-04-09
An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configure…
- CVE-2024-49355MEDIUMCVSS 5.3EG 5.32025-02-20
IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing feature.
- CVE-2024-56473MEDIUMCVSS 5.3EG 5.32025-02-05
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.
- CVE-2024-56277MEDIUMCVSS 5.3EG 5.32025-01-21
Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: from n/a through < 5.5.5.
- CVE-2024-40088MEDIUMCVSS 5.3EG 5.32024-10-21
A Directory Traversal vulnerability in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to enumerate the existence and length of any file in the filesystem by placing malicious payloads in …
- CVE-2024-8297MEDIUMCVSS 5.3EG 5.32024-08-29
A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the …
Map vulnerabilities like CWE-116 to your infrastructure
EchelonGraph correlates every CVE — across CWE-116 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →