CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2026-54699
HIGH
Warp: OS command injection when opening terminal links from WSL
CVSS 7.7
CVE-2026-54013
HIGH
Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI
CVSS 7.6
CVE-2026-52846
MEDIUM
Caddy: stripHTML template function bypass
CVSS 4.2
CVE-2026-56379
HIGH
ImageMagick - Command Injection via SVG Decoder
CVSS 8.1
CVE-2026-44311
MEDIUM
Fabric.js: Improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
CVSS 5.4
CVE-2026-54287
MEDIUM
Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
CVSS 5.3
CVE-2026-44913
HIGH
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
CVSS 7.2
CVE-2026-12048
CRITICAL
pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser
CVSS 9.3
CVE-2026-12047
LOW
pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text
CVSS 3.5
CVE-2026-12044
HIGH
pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates
CVSS 8.8
CVE-2026-45011
HIGH
Apostrophe has stored XSS via javascript: URL in Image Widget Link
CVSS 7.3
CVE-2026-54133
CRITICAL
jmespath.php has CompilerRuntime code injection via unescaped function names
CVSS 9.8
CVE-2026-48485
LOW
Quest Bot: Stored warn reasons can still trigger bot-powered mass mentions through `/warns`.
CVE-2026-47188
LOW
Quest Bot: Unban and unwarn reason fields still allow bot-powered mass mentions.
CVE-2026-47175
LOW
Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` pings
CVE-2026-47173
MEDIUM
Quest Bot: Ticket reason allows mass-mention injection
CVE-2026-47171
HIGH
Quest Bot: Reminder messages allow stored mass mentions through `@everyone` and `@here`
CVE-2026-42558
HIGH
Xibo Vulnerable to Stored XSS and Iframe Sandbox Escape via Data Connector Script in DataSet
CVSS 7.6
CVE-2026-53693
MEDIUM
MISP BSimVis stored cross-site scripting in tag and cluster rendering paths via unescaped tag metadata and UI labels
CVE-2026-49472
MEDIUM
FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat
CVSS 5.3
CVE-2026-8795
HIGH
Rapid7 Velociraptor < 0.76.6 - Improper Encoding or Escaping of Output
CVSS 7.8
CVE-2026-46496
CRITICAL
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
CVE-2026-20245
HIGH
KEV
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
CVSS 7.8
CVE-2026-42321
HIGH
GLPI has stored XSS in asset locks
CVE-2026-48598
LOW
CRLF injection in Tesla.Multipart disposition parameters allows multipart part header injection
Details
Vulnerabilities
482
Exploit Likelihood
High