CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
446 vulnerabilities with CWE-116
CVE-2026-40021
MEDIUM
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
CVSS 5.3
CVE-2026-34481
HIGH
Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout
CVSS 7.5
CVE-2026-34480
HIGH
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
CVSS 7.5
CVE-2026-34479
HIGH
Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
CVSS 7.5
CVE-2026-34483
HIGH
Apache Tomcat: Incomplete escaping of JSON access logs
CVSS 7.5
CVE-2026-35534
HIGH
ChurchCRM has Stored XSS in PersonView.php via Facebook Field Attribute Injection
CVSS 7.6
CVE-2026-35208
MEDIUM
lichess.org Stream Titles - HTML Injection
CVSS 5.4
CVE-2026-26027
HIGH
GLPI 11.0.0-11.0.5 Inventory - Unauthenticated Stored Cross-Site Scripting
CVSS 7.5
CVE-2026-25932
HIGH
GLPI has Stored XSS in Supplier 'Website' field
CVSS 7.2
CVE-2026-33941
HIGH
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
CVSS 8.2
CVE-2026-33758
MEDIUM
OpenBao has Reflected XSS in its OIDC authentication error message
CVSS 6.1
CVE-2026-33628
MEDIUM
Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items
CVSS 5.4
CVE-2026-32986
MEDIUM
Textpattern CMS 4.9.0: Second-Order XSS via Atom Feed Injection
CVSS 6.1
CVE-2026-32811
HIGH
Heimdall: Path received via Envoy gRPC corrupted when containing query string
CVSS 8.2
CVE-2026-29106
MEDIUM
SuiteCRM has blind XSS in return_id parameter
CVSS 5.9
CVE-2026-32754
CRITICAL
FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})
CVSS 9.3
CVE-2026-33301
HIGH
OpenEMR has arbitrary image file read via PDF generator
CVSS 8.1
CVE-2026-31898
HIGH
jsPDF <4.2.1 createAnnotation color - PDF Object Injection
CVSS 8.1
CVE-2026-28499
MEDIUM
Vapor LeafKit < 1.14.2 - Collection Value Cross-Site Scripting
CVSS 6.1
CVE-2026-3644
HIGH
Incomplete control character validation in http.cookies
CVSS 7.5
CVE-2026-31859
MEDIUM
Craft CMS 4.15.3-4.17.3 - Reflected Cross-Site Scripting via Unsanitized Return URL
CVSS 6.1
CVE-2026-28350
MEDIUM
lxml_html_clean <0.4.4 - Auth Bypass
CVSS 6.1
CVE-2026-28348
MEDIUM
lxml_html_clean < 0.4.4 - Cross-Site Scripting via CSS Unicode Escape Sequence Bypass
CVSS 6.1
CVE-2026-27812
CRITICAL
sub2api < 0.1.85 - Password Reset Poisoning via Host Header Manipulation
CVSS 9.1
CVE-2026-21443
MEDIUM
OpenEMR < 8.0.0 - Cross-Site Scripting via Unescaped Translation Function Output
CVSS 6.1
Details
Vulnerabilities
446
Exploit Likelihood
High