CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
414 vulnerabilities with CWE-116
CVE-2026-41426
MEDIUM
pretalx: Email injection via unescaped user-controlled placeholders in pretalx mail templates
CVSS 6.1
CVE-2026-42040
LOW
Axios <1.15.1, <0.31.1 - Info Disclosure
CVSS 3.7
CVE-2026-41318
MEDIUM
AnythingLLM < 1.12.1 - Stored DOM XSS in Chart Caption Renderer
CVSS 5.4
CVE-2026-33597
LOW
PRSD detection denial of service
CVSS 3.7
CVE-2026-40871
HIGH
mailcow: dockerized vulnerable to Second Order SQL Injection in quarantine category via API
CVSS 7.2
CVE-2026-40568
HIGH
FreeScout Vulnerable to XSS via Mailbox Signature Due to Incomplete HTML Sanitization
CVSS 8.5
CVE-2026-40567
MEDIUM
FreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature Variables
CVSS 5.8
CVE-2026-6058
MEDIUM
Zyxel WRE6505 v2 Firmware < V1.00(ABDV.3)C0 - Denial of Service
CVSS 4.5
CVE-2026-35582
HIGH
Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
CVSS 8.8
CVE-2026-40593
MEDIUM
ChurchCRM: Stored XSS in UserEditor.php via Login Name Field
CVSS 4.8
CVE-2026-40483
MEDIUM
ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field
CVSS 5.4
CVE-2026-40302
MEDIUM
zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
CVSS 6.1
CVE-2026-33436
LOW
Stirling-PDF: Reflected XSS through crafted filename in file upload functionality
CVSS 3.1
CVE-2026-35569
HIGH
ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
CVSS 8.7
CVE-2026-20136
MEDIUM
Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability
CVSS 6.0
CVE-2026-2404
MEDIUM
Schneider Electric PowerChute Serial Shutdown <=1.4 - Log Injection
CVSS 5.3
CVE-2026-33657
MEDIUM
EspoCRM: Stored HTML injection in email notifications about stream notes via unescaped post field
CVSS 4.6
CVE-2026-40023
MEDIUM
Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters
CVSS 5.3
CVE-2026-40021
MEDIUM
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
CVSS 5.3
CVE-2026-34481
HIGH
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
CVSS 7.5
CVE-2026-34480
HIGH
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
CVSS 7.5
CVE-2026-34479
MEDIUM
Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
CVE-2026-34483
HIGH
Apache Tomcat: Incomplete escaping of JSON access logs
CVSS 7.5
CVE-2026-35534
HIGH
ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection
CVSS 7.6
CVE-2026-35208
MEDIUM
lichess.org has an Unsanitized Stream Title Injection on /streamer
CVSS 5.4
Details
Vulnerabilities
414
Exploit Likelihood
High