CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

414 vulnerabilities with CWE-116
CVE-2026-26027 HIGH
GLPI has an Unauthenticated Stored XSS via inventory
CVSS 7.5
CVE-2026-25932 HIGH
GLPI has Stored XSS in Supplier 'Website' field
CVSS 7.2
CVE-2026-33941 HIGH
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
CVSS 8.2
CVE-2026-33758 MEDIUM
OpenBao has Reflected XSS in its OIDC authentication error message
CVSS 6.1
CVE-2026-33628 MEDIUM
Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items
CVSS 5.4
CVE-2026-32986 MEDIUM
Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection
CVSS 6.1
CVE-2026-32811 HIGH
Heimdall: Path received via Envoy gRPC corrupted when containing query string
CVSS 8.2
CVE-2026-29106 MEDIUM
SuiteCRM has blind XSS in return_id parameter
CVSS 5.9
CVE-2026-32754 CRITICAL
FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})
CVSS 9.3
CVE-2026-33301 HIGH
OpenEMR has arbitrary image file read via PDF generator
CVSS 8.1
CVE-2026-31898 HIGH
jsPDF has a PDF Object Injection via FreeText color
CVSS 8.1
CVE-2026-28499 MEDIUM
LeafKit's HTML escaping may be skipped for Collection values, enabling XSS
CVSS 6.1
CVE-2026-3644 MEDIUM
Incomplete control character validation in http.cookies
CVE-2026-31859 MEDIUM
Craft CMS - XSS
CVSS 6.1
CVE-2026-28350 MEDIUM
lxml_html_clean <0.4.4 - Auth Bypass
CVSS 6.1
CVE-2026-28348 MEDIUM
lxml_html_clean <0.4.4 - XSS
CVSS 6.1
CVE-2026-27812 CRITICAL
Sub2API <0.1.85 - Auth Bypass
CVSS 9.1
CVE-2026-21443 MEDIUM
OpenEMR <8.0.0 - XSS
CVSS 6.1
CVE-2026-27512 MEDIUM
Tenda F3 V12.01.01.55 - XSS
CVSS 6.1
CVE-2026-27469 MEDIUM
Isso <0afbfe0 - Stored XSS
CVSS 6.1
CVE-2026-27169 HIGH
OpenSift <=1.1.2-alpha - XSS
CVSS 8.9
CVE-2026-27016 MEDIUM
LibreNMS 24.10.0-26.1.1 - Stored XSS
CVSS 5.4
CVE-2026-26953 MEDIUM
Pi-hole Admin Interface 6.0+ - XSS
CVSS 5.4
CVE-2026-26952 MEDIUM
Pi-hole Admin Interface <6.4 - XSS
CVSS 5.4
CVE-2026-27013 HIGH
Fabric.js <7.2.0 - Code Injection
CVSS 7.6
Details
Vulnerabilities 414
Exploit Likelihood High