CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2026-48209
HIGH
OTRS - Reflected XSS in Authenticated Agent Context
CVSS 7.1
CVE-2026-44713
HIGH
pam_usb: Command injection via $TMUX environment variable leads to RCE as root
CVSS 8.8
CVE-2026-45570
CRITICAL
go-git: Improper single-quote escaping in go-git SSH transport
CVSS 9.6
CVE-2026-44972
MEDIUM
GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content
CVSS 5.0
CVE-2026-9354
MEDIUM
NousResearch hermes-agent Slack Agent/Mattermost Agent escape output
CVSS 6.5
CVE-2026-26028
MEDIUM
CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSS
CVSS 6.1
CVE-2026-34246
MEDIUM
CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output
CVSS 4.8
CVE-2026-44429
MEDIUM
MCP Registry: Stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
CVSS 5.4
CVE-2026-45375
CRITICAL
SiYuan: Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
CVSS 9.0
CVE-2026-44588
CRITICAL
SiYuan: URL-encoded title bypasses `escapeAriaLabel`, decoded by `decodeURIComponent` into a tooltip-XSS
CVE-2026-44458
MEDIUM
Hono: CSS Declaration Injection via Style Object Values in JSX SSR
CVSS 4.3
CVE-2026-43939
HIGH
YAF.NET: Stored XSS in Forum Thread Posts/Replies Allowing Arbitrary JavaScript Execution for All Thread Viewers
CVSS 7.3
CVE-2026-43938
HIGH
YAF.NET: Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
CVSS 8.1
CVE-2026-28907
HIGH
iOS and iPadOS < 18.7.9 and < 26.5 - Content Security Policy Bypass via Malicious Web Content
CVSS 8.1
CVE-2026-39826
MEDIUM
Escaper bypass leads to XSS in html/template
CVSS 6.1
CVE-2026-42810
CRITICAL
Apache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or table names
CVSS 9.9
CVE-2026-41426
MEDIUM
pretalx: Email injection via unescaped user-controlled placeholders in pretalx mail templates
CVSS 6.1
CVE-2026-42040
LOW
Axios <1.15.1, <0.31.1 - Info Disclosure
CVSS 3.7
CVE-2026-41318
MEDIUM
AnythingLLM < 1.12.1 - Stored DOM XSS in Chart Caption Renderer
CVSS 5.4
CVE-2026-6019
MEDIUM
BaseCookie.js_output() does not neutralize embedded characters
CVSS 6.1
CVE-2026-33597
LOW
PRSD detection denial of service
CVSS 3.7
CVE-2026-40871
HIGH
mailcow: dockerized vulnerable to Second Order SQL Injection in quarantine category via API
CVSS 7.2
CVE-2026-40568
HIGH
FreeScout Vulnerable to XSS via Mailbox Signature Due to Incomplete HTML Sanitization
CVSS 8.5
CVE-2026-40567
MEDIUM
FreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature Variables
CVSS 5.8
CVE-2026-6058
MEDIUM
Zyxel WRE6505 v2 firmware V1.00(ABDV.3)C0 - Denial of Service via Malformed SSID on AP Select Page
CVSS 4.5
Details
Vulnerabilities
482
Exploit Likelihood
High