CWE-707— Improper Neutralization
The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.— MITRE CWE catalog
263 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-707page 3 of 6
- CVE-2026-7045MEDIUMCVSS 6.3EG 6.32026-04-26
A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/da…
- CVE-2026-6994MEDIUMCVSS 6.3EG 6.32026-04-25
A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes inje…
- CVE-2026-6599MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/base/langflow/api/v1/mcp_projects.py of the component Model Context Protocol Co…
- CVE-2026-5561MEDIUMCVSS 6.3EG 6.32026-04-05
A vulnerability was determined in Campcodes Complete POS Management and Inventory System up to 4.0.6. This affects an unknown function of the file app/Http/Controllers/SettingsController.php of the component Environment Variable Handler. E…
- CVE-2026-4516MEDIUMCVSS 6.3EG 6.32026-03-21
A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file metagpt/actions/di/write_analysis_code.py of the component DataInterpreter. The manipulation results in injection. It i…
- CVE-2026-4511MEDIUMCVSS 6.3EG 6.32026-03-21
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The attack can be executed remotely. The exploit has been disclose…
- CVE-2026-4500MEDIUMCVSS 6.3EG 6.32026-03-20
A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.py. Such manipulation leads to injection. The attack may be launched rem…
- CVE-2026-3992MEDIUMCVSS 6.3EG 6.32026-03-12
A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file utils/dynamodb.ts of the component Users Endpoint. This manipulation of the argument filter causes injection. The atta…
- CVE-2025-14674MEDIUMCVSS 6.3EG 6.32025-12-14
A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/st…
- CVE-2025-13268MEDIUMCVSS 6.3EG 6.32025-11-17
A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/main/java/com/vince/xq/project/system/dbconfig/service/DbconfigServiceImpl.java of the component JDBC URL Handler. Exec…
- CVE-2025-11445MEDIUMCVSS 6.3EG 6.32025-10-08
A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be i…
- CVE-2024-10810MEDIUMCVSS 6.3EG 6.32024-11-05
A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. The manipulation of the argument app_id leads to sql injection. It…
- CVE-2024-10809MEDIUMCVSS 6.3EG 6.32024-11-05
A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The manipulation of the argument name/message leads to sql injection. …
- CVE-2024-10808MEDIUMCVSS 6.3EG 6.32024-11-05
A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The manipulation of the argument id leads to sql injection. The …
- CVE-2024-10805MEDIUMCVSS 6.3EG 6.32024-11-04
A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part of the file doedit.php. The manipulation of the argument id leads to sql injection. It is p…
- CVE-2024-10700MEDIUMCVSS 6.3EG 6.32024-11-02
A vulnerability was found in code-projects University Event Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file submit.php. The manipulation of the argument name/email/title/Year/gen…
- CVE-2024-9324MEDIUMCVSS 6.3EG 6.32024-09-29
A vulnerability was found in Intelbras InControl up to 2.21.57. It has been rated as critical. Affected by this issue is some unknown functionality of the file /v1/operador/ of the component Relatório de Operadores Page. The manipulation …
- CVE-2022-4375MEDIUMCVSS 6.3EG 6.32022-12-09
A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to…
- CVE-2022-3997MEDIUMCVSS 6.3EG 6.32022-11-15
A vulnerability, which was classified as critical, has been found in MonikaBrzica scm. Affected by this issue is some unknown functionality of the file upis_u_bazu.php. The manipulation of the argument email/lozinka/ime/id leads to sql inj…
- CVE-2022-3827MEDIUMCVSS 6.3EG 6.32022-11-02
A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the file formContactGroup.php of the component Contact Groups Form. The manipulation of the argument cg_id leads to sql inj…
- CVE-2022-3802MEDIUMCVSS 6.3EG 6.32022-11-01
A vulnerability has been found in IBAX go-ibax and classified as critical. This vulnerability affects unknown code of the file /api/v2/open/rowsInfo. The manipulation of the argument where leads to sql injection. The attack can be initiate…
- CVE-2022-3801MEDIUMCVSS 6.3EG 6.32022-11-01
A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /api/v2/open/rowsInfo. The manipulation of the argument order leads to sql injection. It is possible to initiate the att…
- CVE-2022-3800MEDIUMCVSS 6.3EG 6.32022-11-01
A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. …
- CVE-2022-3799MEDIUMCVSS 6.3EG 6.32022-11-01
A vulnerability classified as critical was found in IBAX go-ibax. Affected by this vulnerability is an unknown functionality of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. The attack can be launched remotely.…
- CVE-2022-3798MEDIUMCVSS 6.3EG 6.32022-11-01
A vulnerability classified as critical has been found in IBAX go-ibax. Affected is an unknown function of the file /api/v2/open/tablesInfo. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit …
- CVE-2022-3472MEDIUMCVSS 6.3EG 6.32022-10-13
A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file city.php. The manipulation of the argument cityedit leads to sql …
- CVE-2022-3471MEDIUMCVSS 6.3EG 6.32022-10-13
A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file city.php. The manipulation of the argument searccity lea…
- CVE-2020-36626MEDIUMCVSS 5.5EG 6.12022-12-27
A vulnerability classified as critical has been found in Modern Tribe Panel Builder Plugin. Affected is the function add_post_content_filtered_to_search_sql of the file ModularContent/SearchFilter.php. The manipulation leads to sql injecti…
- CVE-2021-4273MEDIUMCVSS 4.3EG 6.12022-12-21
A vulnerability classified as problematic was found in studygolang. This vulnerability affects the function Search of the file http/controller/search.go. The manipulation of the argument q leads to cross site scripting. The attack can be i…
- CVE-2022-3942MEDIUMCVSS 4.3EG 6.12022-11-11
A vulnerability was found in SourceCodester Sanitization Management System and classified as problematic. This issue affects some unknown processing of the file php-sms/?p=request_quote. The manipulation leads to cross site scripting. The …
- CVE-2022-3804MEDIUMCVSS 4.3EG 6.12022-11-01
A vulnerability was found in eolinker apinto-dashboard. It has been classified as problematic. Affected is an unknown function of the file /login. The manipulation of the argument callback leads to cross site scripting. It is possible to l…
- CVE-2022-3464MEDIUMCVSS 4.3EG 6.12022-10-12
A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The manipulation of the argument site_name leads to cross site scripting. It is possible to initi…
- CVE-2022-4727MEDIUMCVSS 3.5EG 6.12022-12-27
A vulnerability, which was classified as problematic, was found in OpenMRS Appointment Scheduling Module up to 1.16.x. This affects the function getNotes of the file api/src/main/java/org/openmrs/module/appointmentscheduling/AppointmentReq…
- CVE-2022-4631MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file ban-options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name …
- CVE-2021-4274MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability, which was classified as problematic, has been found in sileht bird-lg. This issue affects some unknown processing of the file templates/layout.html. The manipulation of the argument request_args leads to cross site scripti…
- CVE-2021-4272MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability classified as problematic has been found in studygolang. This affects an unknown part of the file static/js/topics.js. The manipulation of the argument contentHtml leads to cross site scripting. It is possible to initiate t…
- CVE-2021-4271MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability was found in panicsteve w2wiki. It has been rated as problematic. Affected by this issue is the function toHTML of the file index.php of the component Markdown Handler. The manipulation leads to cross site scripting. The at…
- CVE-2021-4270MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability was found in Imprint CMS. It has been classified as problematic. Affected is the function SearchForm of the file ImprintCMS/Models/ViewHelpers.cs. The manipulation of the argument query leads to cross site scripting. It is …
- CVE-2021-4269MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability has been found in SimpleRisk and classified as problematic. This vulnerability affects the function checkAndSetValidation of the file simplerisk/js/common.js. The manipulation of the argument title leads to cross site scrip…
- CVE-2021-4267MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability classified as problematic was found in tad_discuss. Affected by this vulnerability is an unknown functionality. The manipulation of the argument DiscussTitle leads to cross site scripting. The attack can be launched remotel…
- CVE-2021-4266MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argume…
- CVE-2021-4265MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability was found in siwapp-ror. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 924d16008…
- CVE-2020-36621MEDIUMCVSS 3.5EG 6.12022-12-21
A vulnerability, which was classified as problematic, has been found in chedabob whatismyudid. Affected by this issue is the function exports.enrollment of the file routes/mobileconfig.js. The manipulation leads to cross site scripting. Th…
- CVE-2021-4257MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability was found in ctrlo lenio. It has been declared as problematic. This vulnerability affects unknown code of the file views/task.tt of the component Task Handler. The manipulation of the argument site.org.name/check.name/task.…
- CVE-2021-4256MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability was found in ctrlo lenio. It has been classified as problematic. This affects an unknown part of the file views/index.tt. The manipulation of the argument task.name/task.site.org.name leads to cross site scripting. It is po…
- CVE-2021-4255MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability was found in ctrlo lenio and classified as problematic. Affected by this issue is some unknown functionality of the file views/contractor.tt. The manipulation of the argument contractor.name leads to cross site scripting. T…
- CVE-2021-4254MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability has been found in ctrlo lenio and classified as problematic. Affected by this vulnerability is an unknown functionality of the file views/layouts/main.tt of the component Notice Handler. The manipulation of the argument not…
- CVE-2021-4253MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability, which was classified as problematic, was found in ctrlo lenio. Affected is an unknown function in the library lib/Lenio.pm of the component Ticket Handler. The manipulation of the argument site_id leads to cross site scrip…
- CVE-2021-4252MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability, which was classified as problematic, has been found in WP-Ban. This issue affects the function toggle_checkbox of the file ban-options.php. The manipulation of the argument $_SERVER["HTTP_USER_AGENT"] leads to cross site s…
- CVE-2021-4251MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability classified as problematic was found in as. This vulnerability affects the function getFullURL of the file include.cdn.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of th…
Map vulnerabilities like CWE-707 to your infrastructure
EchelonGraph correlates every CVE — across CWE-707 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →