CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

414 vulnerabilities with CWE-116
CVE-2026-25940 HIGH
jsPDF <4.2.0 - Code Injection
CVSS 8.1
CVE-2026-25755 HIGH
jsPDF <4.2.0 - Code Injection
CVSS 8.1
CVE-2026-25230 MEDIUM
FileRise <3.3.0 - Code Injection
CVSS 4.6
CVE-2026-25543 MEDIUM
Nuget Htmlsanitizer < 9.0.892 - XSS
CVSS 6.1
CVE-2026-24737 HIGH
jsPDF <4.1.0 - Code Injection
CVSS 8.1
CVE-2026-0818 MEDIUM
Mozilla Thunderbird < 140.7.1 - Information Disclosure
CVSS 4.3
CVE-2026-24439 MEDIUM
Shenzhen Tenda W30E V2 <16.01.0.19(5037) - XSS
CVSS 6.5
CVE-2026-24127 MEDIUM
Typemill <2.19.1 - XSS
CVSS 5.4
CVE-2026-23630 MEDIUM
Docmost 0.3.0-0.23.2 - XSS
CVSS 5.4
CVE-2026-22792 CRITICAL
5ire <0.15.3 - XSS
CVSS 9.6
CVE-2026-23880 HIGH
OnboardLite <commit 1d32081a66f21bcf41df1ecb672490b13f6e429f - XSS
CVSS 7.3
CVE-2026-1011 MEDIUM
Altium Live < 1.1.1.39 - XSS
CVSS 6.1
CVE-2026-22712 MEDIUM
Mediawiki - ApprovedRevs Extension <1.45 - XSS
CVSS 4.3
CVE-2025-12697 LOW
GitLab CE/EE - Info Disclosure
CVSS 2.2
CVE-2025-15312 MEDIUM
Tanium Appliance - Info Disclosure
CVSS 6.6
CVE-2025-66488 MEDIUM
Discourse <3.5.4-2026.1.0 - Info Disclosure
CVSS 4.6
CVE-2025-59158 HIGH
Coollabs Coolify < 4.0.0 - XSS
CVSS 8.0
CVE-2025-68460 HIGH
Roundcube Webmail < 1.5.12 - Information Disclosure
CVSS 7.2
CVE-2025-12734 LOW
GitLab CE/EE <18.4.6-18.6.2 - XSS
CVSS 3.5
CVE-2025-8405 HIGH
GitLab CE/EE <18.4.6-18.6.2 - Privilege Escalation
CVSS 7.7
CVE-2025-42896 MEDIUM
SAP BusinessObjects - SSRF
CVSS 5.4
CVE-2025-66548 LOW
Nextcloud Deck <1.12.7, 1.14.4, 1.15.1 - Info Disclosure
CVSS 3.3
CVE-2025-9127 MEDIUM
PX Enterprise - Info Disclosure
CVSS 5.5
CVE-2025-13742 MEDIUM
Pretix < 2025.7.2 - XSS
CVSS 6.1
CVE-2025-64325 CRITICAL
Emby Server <4.8.1.0-4.9.0.0-beta - Info Disclosure
CVSS 9.0
Details
Vulnerabilities 414
Exploit Likelihood High