CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2026-54364
MEDIUM
CentreStack < 17.4 Session Injection via SelectProvider.aspx
CVSS 6.5
CVE-2026-54705
MEDIUM
MathLive < 0.110.0 - Cross-Site Scripting via HTML Escaping Failure
CVSS 6.3
CVE-2026-50642
MEDIUM
Terminal Escape Injection in diff‑so‑fancy
CVE-2026-59727
LOW
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-64647
MEDIUM
Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies
CVSS 5.4
CVE-2026-55730
HIGH
Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802
CVE-2026-12496
HIGH
Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server
CVE-2026-63397
MEDIUM
remorses/genql code injection
CVSS 6.4
CVE-2026-15809
HIGH
CRI-O - HOME Environment Variable /etc/passwd Injection
CVSS 7.8
CVE-2026-46637
MEDIUM
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
CVSS 5.4
CVE-2026-46628
MEDIUM
Twig: The `spaceless` filter implicitly marks its output as safe
CVSS 5.4
CVE-2026-50659
MEDIUM
Microsoft .NET 10.0 - .NET Spoofing Vulnerability
CVSS 6.5
CVE-2026-48358
CRITICAL
Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)
CVSS 9.1
CVE-2026-62184
HIGH
luci-app-banip Log Monitor IP Extraction Bypass
CVSS 7.5
CVE-2026-58487
MEDIUM
HedgeDoc: Stored HTML injection via email local-part
CVE-2026-49844
MEDIUM
Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()
CVSS 5.9
CVE-2026-55659
HIGH
Grist: XSS through unsafe value interpolation in server-rendered pages
CVSS 7.7
CVE-2026-59833
HIGH
SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)
CVE-2026-59895
MEDIUM
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVSS 6.1
CVE-2026-54893
LOW
Email-derived URL path injection in the Swoosh Microsoft Graph adapter
CVE-2026-49091
HIGH
Improper Output Neutralization for Logs in Kibana Leading to Log Injection
CVSS 8.0
CVE-2026-47206
LOW
Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer
CVE-2026-28898
MEDIUM
Apple swift-nio-http2 < 1.44.1 - Improper Encoding or Escaping of Output
CVSS 5.3
CVE-2026-40011
LOW
PowerDNS DNSdist - Prometheus Denial of Service via Crafted DNS Queries
CVSS 3.7
CVE-2026-55570
CRITICAL
SiYuan < 3.7.0 - Electron Remote Code Execution via data-obj XSS
CVSS 9.0
Details
Vulnerabilities
482
Exploit Likelihood
High