CWE-184— Incomplete List of Disallowed Inputs
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.— MITRE CWE catalog
225 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-184page 5 of 5
- CVE-2026-31993MEDIUMCVSS 4.8EG 4.82026-03-19
OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that allows authenticated operators to bypass exec approval checks. Attackers with operator.write privileges and a paired m…
- CVE-2026-68921MEDIUMCVSS 4.7EG 4.72026-08-20
DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, while …
- CVE-2022-38179MEDIUMCVSS 4.7EG 4.72022-08-12
JetBrains Ktor before 2.1.0 was vulnerable to the Reflect File Download attack
- CVE-2021-1135MEDIUMCVSS 4.6EG 4.62021-01-20
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vul…
- CVE-2021-1255MEDIUMCVSS 4.6EG 4.62021-01-20
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vul…
- CVE-2021-1133MEDIUMCVSS 4.6EG 4.62021-01-20
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vul…
- CVE-2026-72779MEDIUMCVSS 4.5EG 4.52026-08-11
Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an…
- CVE-2025-69277MEDIUMCVSS 4.5EG 4.52025-12-31
libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows point…
- CVE-2026-53848MEDIUMCVSS 4.3EG 4.32026-06-16
OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command requests that bypass allowlist…
- CVE-2026-34425MEDIUMCVSS 4.3EG 4.32026-04-02
OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection that allows attackers to execute blocked script content by using piped or complex command forms that the parser fails t…
- CVE-2016-6189MEDIUMCVSS 4.3EG 4.32017-02-17
Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.
- CVE-2022-34888MEDIUMCVSS 2.7EG 4.32023-01-30
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.
- CVE-2026-105648MEDIUMCVSS 4.0EG 4.02026-10-05
Ghost is a Node.js content management system. From 6.0.9 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's…
- CVE-2020-5253LOWCVSS 3.9EG 3.92020-03-10
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.
- CVE-2025-61924LOWCVSS 3.8EG 3.82025-10-16
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The …
- CVE-2025-24388LOWCVSS 3.8EG 3.82025-06-16
A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X …
- CVE-2026-18356LOWCVSS 3.7EG 3.72026-08-21
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to…
- CVE-2026-56547LOWCVSS 3.5EG 3.52026-08-26
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them. The values cannot be changed later on, so the Apple …
- CVE-2026-40077LOWCVSS 3.5EG 3.52026-04-09
Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied system ID and proceed without further checks that the user should have access to that system. As a result, any authenticat…
- CVE-2024-32152LOWCVSS 3.1EG 3.12024-07-22
A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted malicious flashcard can lead to an arbitrary file creation at a fixed path. An attacker can share a malicious flashcard to trig…
- CVE-2017-2602LOWCVSS 3.1EG 3.12018-05-15
jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).
- CVE-2021-25737LOWCVSS 2.7EG 2.72021-09-06
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validatio…
- CVE-2026-57234LOWCVSS 2.6EG 2.62026-06-25
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-26247), was not correctly enforced on th…
- CVE-2026-73492LOWCVSS 2.3EG 2.32026-08-12
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose schem…
- CVE-2026-73491LOWCVSS 2.3EG 2.32026-08-12
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or…
Map vulnerabilities like CWE-184 to your infrastructure
EchelonGraph correlates every CVE — across CWE-184 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →