CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2022-43883 MEDIUM
IBM Cognos Analytics <11.2.1 - Log Injection
CVSS 6.5
CVE-2022-41934 CRITICAL
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
CVSS 9.9
CVE-2022-40870 HIGH
Parallels Remote Application Server <18.0 - Command Injection
CVSS 8.1
CVE-2022-0421 MEDIUM
Five Star Restaurant Reservations WP <2.4.12 - XSS
CVSS 6.1
CVE-2022-4011 MEDIUM
Simple History Plugin - Info Disclosure
CVSS 6.5
CVE-2022-34316 LOW
IBM CICS TX 11.1 - Cross-Site Scripting via HTTP Headers
CVSS 3.7
CVE-2022-3941 MEDIUM
Activity Log Plugin - Info Disclosure
CVSS 5.3
CVE-2022-41443 CRITICAL
phpipam 1.5.0 - Header Injection via ripe-query.php Component
CVSS 9.8
CVE-2022-41322 HIGH
kitty < 0.26.2 - Remote Code Execution via Desktop Notification Escape Sequence
CVSS 7.8
CVE-2022-39958 HIGH
OWASP ModSecurity Core Rule Set 3.0.0-3.2.1 and 3.3.2 - Response Body Exfiltration via HTTP Range Header Bypass
CVSS 7.5
CVE-2022-39957 HIGH
OWASP ModSecurity Core Rule Set - Auth Bypass
CVSS 7.3
CVE-2022-39956 HIGH
OWASP ModSecurity Core Rule Set 3.0.0-3.2.1 & 3.3.2 - Bypass via Character Encoding in MIME Headers
CVSS 7.3
CVE-2022-36100 CRITICAL
XWiki Platform <14.4 - Code Injection
CVSS 9.9
CVE-2022-36099 CRITICAL
XWiki Platform Wiki UI Main Wiki <13.10.6-14.4 - Code Injection
CVSS 9.9
CVE-2022-35153 CRITICAL
FusionPBX 5.0.1 - OS Command Injection via Fax Send Endpoint
CVSS 9.8
CVE-2022-2619 MEDIUM
Google Chrome < 104.0.5112.79 - Script Injection via Malicious Extension
CVSS 4.3
CVE-2022-2241 MEDIUM
Featured Image from URL (FIFU) < 4.0.1 - Cross-Site Request Forgery and Stored Cross-Site Scripting
CVSS 6.1
CVE-2022-36446 CRITICAL
Webmin < 1.997 - Remote Code Execution via Unescaped UI Command
CVSS 9.8
CVE-2022-2099 MEDIUM
WooCommerce < 6.6.0 - Stored Cross-Site Scripting in Payment Gateway Titles
CVSS 4.8
CVE-2022-20230 MEDIUM
Android - Local Information Disclosure via KeyChain choosePrivateKeyAlias
CVSS 5.5
CVE-2022-34820 HIGH
SIMATIC and SIPLUS CP Firmware - Remote Code Execution via Authentication Field Injection
CVSS 8.4
CVE-2022-32549 MEDIUM
Apache Sling Commons Log <= 5.4.0 & Apache Sling API <= 2.25.0 - Co...
CVSS 5.3
CVE-2022-23079
motor-admin <0.2.56 - Host Header Injection
CVE-2022-29258 HIGH
XWiki Platform <12.10.11-14.0-rc-1-13.4.7-13.10.3 - XSS
CVSS 7.4
CVE-2022-29252 HIGH
XWiki Platform Wiki UI Main Wiki <5.3-milestone-2 - XSS
CVSS 7.4
Details
Vulnerabilities 482
Exploit Likelihood High