CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2022-29251 HIGH
XWiki Platform Flamingo Theme UI <12.10.11,14.0-rc-1,13.4.7,13.10.3...
CVSS 7.4
CVE-2022-29599 CRITICAL
Apache Maven maven-shared-utils <3.3.3 - Command Injection
CVSS 9.8
CVE-2022-28960 HIGH
SPIP < 3.2.8 - Remote Code Execution via _oups Parameter
CVSS 8.8
CVE-2022-30966 MEDIUM
Jenkins Random String Parameter Plugin <1.0 - XSS
CVSS 5.4
CVE-2022-30781 HIGH
Gitea < 1.16.7 - Remote Code Execution via Git Fetch Remote
CVSS 7.5
CVE-2022-0935 HIGH
livehelperchat/livehelperchat <3.97 - SSRF
CVSS 8.8
CVE-2022-0741 MEDIUM
GitLab 10.0.0-14.6.5 - Environment Variable Exposure via Sendmail Email Address Injection
CVSS 5.8
CVE-2022-0450 MEDIUM
Menu Image Icons made easy <3.0.6 - CSRF
CVSS 5.4
CVE-2022-26174 CRITICAL
Beekeeper Studio < 3.7.10 - Remote Code Execution via Display Field Injection
CVSS 9.8
CVE-2022-22734 MEDIUM
Simple Quotation < 1.3.2 - Cross-Site Scripting via Quote Creation/Editing
CVSS 6.1
CVE-2022-22151 HIGH
Yokogawa Electric - Info Disclosure
CVSS 8.1
CVE-2022-25235 CRITICAL
libexpat < 2.4.5 - Improper Encoding or Escaping of Output
CVSS 9.8
CVE-2022-23620 MEDIUM
XWiki < 13.6 - Path Traversal via SSX Document Reference Export
CVSS 6.8
CVE-2022-24682 MEDIUM KEV
Zimbra Collaboration Suite <8.8.15 patch 30 (update 1) - XSS
CVSS 6.1
CVE-2022-0220 MEDIUM
WordPress GDPR & CCPA < 1.9.26 - Unauthenticated Stored Cross-Site Scripting via check_privacy_settings AJAX Action
CVSS 6.1
CVE-2022-23603 CRITICAL
iTunesRPC-Remastered - Code Injection
CVSS 9.9
CVE-2022-22992 HIGH
Western Digital My Cloud OS < 5.19.117 - Remote Code Execution via Improper Shell Argument Escaping
CVSS 7.8
CVE-2022-0210 MEDIUM
Random Banner WordPress <4.1.4 - XSS
CVSS 4.8
CVE-2022-0124 MEDIUM
GitLab <14.4.5, 14.5.0-14.5.3, 14.6.0-14.6.1 - Open Redirect
CVSS 4.3
CVE-2021-47694 MEDIUM
Nagios XI < 5.8.6 - Reflected Cross-Site Scripting via CCM Test Command
CVSS 6.1
CVE-2021-25262 MEDIUM
Yandex Browser for Android <21.3.0 - Open Redirect
CVSS 5.4
CVE-2021-25254 MEDIUM
Yandex Browser Lite for Android < 21.1.0 - Address Bar Spoofing
CVSS 5.3
CVE-2021-38997 MEDIUM
IBM API Connect <10.0.5.0 - HTTP Header Injection
CVSS 5.4
CVE-2021-42010 CRITICAL
Apache Heron <= 0.20.4-incubating - CRLF Log Injection
CVSS 9.8
CVE-2021-40694 MEDIUM
moodle < 3.9.10 - Unauthenticated Arbitrary File Read via LaTeX Preamble
CVSS 4.9
Details
Vulnerabilities 482
Exploit Likelihood High