CWE-707— Improper Neutralization
The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.— MITRE CWE catalog
263 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-707page 4 of 6
- CVE-2022-4595MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability classified as problematic has been found in django-openipam. This affects an unknown part of the file openipam/report/templates/report/exposed_hosts.html. The manipulation of the argument description leads to cross site scr…
- CVE-2022-4593MEDIUMCVSS 3.5EG 6.12022-12-18
A vulnerability was found in retra-system. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is a6d94…
- CVE-2022-4591MEDIUMCVSS 3.5EG 6.12022-12-17
A vulnerability was found in mschaef toto up to 1.4.20. It has been declared as problematic. This vulnerability affects unknown code of the component Email Parameter Handler. The manipulation leads to cross site scripting. The attack can b…
- CVE-2022-4590MEDIUMCVSS 3.5EG 6.12022-12-17
A vulnerability was found in mschaef toto up to 1.4.20. It has been classified as problematic. This affects an unknown part of the component Todo List Handler. The manipulation leads to cross site scripting. It is possible to initiate the …
- CVE-2022-4586MEDIUMCVSS 3.5EG 6.12022-12-17
A vulnerability classified as problematic was found in Opencaching Deutschland oc-server3. This vulnerability affects unknown code of the file htdocs/templates2/ocstyle/cachelists.tpl of the component Cachelist Handler. The manipulation of…
- CVE-2022-4585MEDIUMCVSS 3.5EG 6.12022-12-17
A vulnerability classified as problematic has been found in Opencaching Deutschland oc-server3. This affects an unknown part of the file htdocs/templates2/ocstyle/start.tpl of the component Cookie Handler. The manipulation of the argument …
- CVE-2022-4582MEDIUMCVSS 3.5EG 6.12022-12-17
A vulnerability was found in starter-public-edition-4 up to 4.6.10. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgra…
- CVE-2022-4581MEDIUMCVSS 3.5EG 6.12022-12-17
A vulnerability was found in 1j01 mind-map and classified as problematic. This issue affects some unknown processing of the file app.coffee. The manipulation of the argument html leads to cross site scripting. The attack may be initiated r…
- CVE-2022-4561MEDIUMCVSS 3.5EG 6.12022-12-16
A vulnerability classified as problematic has been found in SemanticDrilldown Extension. Affected is the function printFilterLine of the file includes/specials/SDBrowseDataPage.php of the component GET Parameter Handler. The manipulation o…
- CVE-2022-4559MEDIUMCVSS 3.5EG 6.12022-12-16
A vulnerability was found in INEX IPX-Manager up to 6.2.0. It has been declared as problematic. This vulnerability affects unknown code of the file resources/views/customer/list.foil.php. The manipulation leads to cross site scripting. The…
- CVE-2022-4558MEDIUMCVSS 3.5EG 6.12022-12-16
A vulnerability was found in Alinto SOGo up to 5.7.1. It has been classified as problematic. This affects an unknown part of the file SoObjects/SOGo/NSString+Utilities.m of the component Folder/Mail Handler. The manipulation leads to cross…
- CVE-2022-4556MEDIUMCVSS 3.5EG 6.12022-12-16
A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the function _migrateMailIdentities of the file SoObjects/SOGo/SOGoUserDefaults.m of the component Identity Handler. The manipula…
- CVE-2022-4523MEDIUMCVSS 3.5EG 6.12022-12-15
A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 21c0…
- CVE-2022-4522MEDIUMCVSS 3.5EG 6.12022-12-15
A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 10.0.2 is a…
- CVE-2022-4514MEDIUMCVSS 3.5EG 6.12022-12-15
A vulnerability, which was classified as problematic, was found in Opencaching Deutschland oc-server3. Affected is an unknown function of the file htdocs/lang/de/ocstyle/varset.inc.php. The manipulation of the argument varvalue leads to cr…
- CVE-2022-4513MEDIUMCVSS 3.5EG 6.12022-12-15
A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This issue affects some unknown processing. The manipulation of the argument searchTag/resourceUri leads to cross site scri…
- CVE-2022-4456MEDIUMCVSS 3.5EG 6.12022-12-13
A vulnerability has been found in falling-fruit and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 15adb8e1…
- CVE-2022-4444MEDIUMCVSS 3.5EG 6.12022-12-13
A vulnerability was found in ipti br.tag. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to ve…
- CVE-2022-4421MEDIUMCVSS 3.5EG 6.12022-12-12
A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of the file themes/default/servicedesk/view.php of the component Service Desk Image URL Handler. The manipulation of the ar…
- CVE-2022-4400MEDIUMCVSS 3.5EG 6.12022-12-11
A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing of the component Title Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. Th…
- CVE-2022-4348MEDIUMCVSS 3.5EG 6.12022-12-08
A vulnerability was found in y_project RuoYi-Cloud. It has been rated as problematic. Affected by this issue is some unknown functionality of the component JSON Handler. The manipulation leads to cross site scripting. The attack may be lau…
- CVE-2022-4341MEDIUMCVSS 3.5EG 6.12022-12-07
A vulnerability has been found in csliuwy coder-chain_gdut and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /back/index.php/user/User/?1. The manipulation leads to cross site scripting. …
- CVE-2022-4279MEDIUMCVSS 3.5EG 6.12022-12-03
A vulnerability classified as problematic has been found in SourceCodester Human Resource Management System 1.0. Affected is an unknown function of the file /hrm/employeeview.php. The manipulation of the argument search leads to cross site…
- CVE-2022-4252MEDIUMCVSS 3.5EG 6.12022-12-01
A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function builtin_echo of the file categories.php. The manipulation leads to cross site scripting. It is possible…
- CVE-2022-4250MEDIUMCVSS 3.5EG 6.12022-12-01
A vulnerability has been found in Movie Ticket Booking System and classified as problematic. Affected by this vulnerability is an unknown functionality of the file booking.php. The manipulation of the argument id leads to cross site script…
- CVE-2022-4249MEDIUMCVSS 3.5EG 6.12022-12-01
A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown function of the component POST Request Handler. The manipulation of the argument ORDER_ID leads to cross site scripting.…
- CVE-2022-4234MEDIUMCVSS 3.5EG 6.12022-11-30
A vulnerability was found in SourceCodester Canteen Management System. It has been rated as problematic. This issue affects the function builtin_echo of the file youthappam/brand.php. The manipulation of the argument brand_name leads to cr…
- CVE-2022-4091MEDIUMCVSS 3.5EG 6.12022-11-25
A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affects the function query of the file food.php. The manipulation of the argument product_name leads to cross site scripting…
- CVE-2022-3988MEDIUMCVSS 3.5EG 6.12022-11-14
A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the ar…
- CVE-2022-3968MEDIUMCVSS 3.5EG 6.12022-11-13
A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/article_save.php. The manipulation of the argument tag leads to cross site scripting. The a…
- CVE-2022-3950MEDIUMCVSS 3.5EG 6.12022-11-11
A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross site scripting. It is possible to …
- CVE-2022-3949MEDIUMCVSS 3.5EG 6.12022-11-11
A vulnerability, which was classified as problematic, has been found in Sourcecodester Simple Cashiering System. This issue affects some unknown processing of the component User Account Handler. The manipulation of the argument fullname le…
- CVE-2022-3803MEDIUMCVSS 3.5EG 6.12022-11-01
A vulnerability was found in eolinker apinto-dashboard and classified as problematic. This issue affects some unknown processing of the file /api/discoveries/. The manipulation leads to cross site scripting. The attack may be initiated rem…
- CVE-2022-3673MEDIUMCVSS 3.5EG 6.12022-10-26
A vulnerability, which was classified as problematic, was found in SourceCodester Sanitization Management System 1.0. Affected is an unknown function of the file /php-sms/classes/Master.php. The manipulation of the argument message leads t…
- CVE-2022-3672MEDIUMCVSS 3.5EG 6.12022-10-26
A vulnerability, which was classified as problematic, has been found in SourceCodester Sanitization Management System 1.0. This issue affects some unknown processing of the file /php-sms/classes/SystemSettings.php. The manipulation of the …
- CVE-2022-3442MEDIUMCVSS 3.5EG 6.12022-10-10
A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ebics-server/ebics.aspx. The manipulation leads to cross site scripting. The attack may b…
- CVE-2022-4233MEDIUMCVSS 2.4EG 6.12022-11-30
A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /event/admin/?page=user/list. The manipulation of the argu…
- CVE-2022-3992MEDIUMCVSS 2.4EG 6.12022-11-14
A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this vulnerability is an unknown functionality of the file admin/?page=system_info of the component Banner Image Handler. The…
- CVE-2022-3845MEDIUMCVSS 2.4EG 6.12022-11-02
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manip…
- CVE-2022-3581MEDIUMCVSS 2.4EG 6.12022-10-18
A vulnerability, which was classified as problematic, was found in SourceCodester Cashier Queuing System 1.0. Affected is an unknown function of the component Cashiers Tab. The manipulation of the argument Name leads to cross site scriptin…
- CVE-2022-3580MEDIUMCVSS 2.4EG 6.12022-10-18
A vulnerability, which was classified as problematic, has been found in SourceCodester Cashier Queuing System 1.0.1. This issue affects some unknown processing of the component User Creation Handler. The manipulation leads to cross site sc…
- CVE-2022-3519MEDIUMCVSS 2.4EG 6.12022-10-15
A vulnerability classified as problematic was found in SourceCodester Sanitization Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Quote Requests Tab. The manipulation of the argument Mana…
- CVE-2022-3518MEDIUMCVSS 2.4EG 6.12022-10-15
A vulnerability classified as problematic has been found in SourceCodester Sanitization Management System 1.0. Affected is an unknown function of the component User Creation Handler. The manipulation of the argument First Name/Middle Name/…
- CVE-2025-27712MEDIUMCVSS 5.7EG 5.72025-11-11
Improper neutralization for some Intel(R) Neural Compressor software before version v3.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low …
- CVE-2026-10222MEDIUMCVSS 5.6EG 5.62026-06-01
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch …
- CVE-2026-92213MEDIUMCVSS 5.5EG 5.52026-09-16
A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argument…
- CVE-2024-10841MEDIUMCVSS 5.5EG 5.52024-11-05
A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an unknown functionality of the file /Proses_Kirim.php of the component Mail Handler. The manipulation of the argument Name …
- CVE-2023-45315MEDIUMCVSS 5.5EG 5.52024-05-16
Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-4587MEDIUMCVSS 4.3EG 5.42022-12-17
A vulnerability, which was classified as problematic, has been found in Opencaching Deutschland oc-server3. This issue affects some unknown processing of the file htdocs/templates2/ocstyle/login.tpl of the component Login Page. The manipul…
- CVE-2022-4089MEDIUMCVSS 4.3EG 5.42022-11-24
A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads to cross site script…
Map vulnerabilities like CWE-707 to your infrastructure
EchelonGraph correlates every CVE — across CWE-707 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →