CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

446 vulnerabilities with CWE-116
CVE-2026-27512 MEDIUM
Tenda F3 Firmware < 12.01.01.55_multi - Reflected Script Execution via Missing nosniff Header
CVSS 6.1
CVE-2026-27469 MEDIUM
Isso < 0.13.2 - Stored Cross-Site Scripting via Website and Author Comment Fields
CVSS 6.1
CVE-2026-27169 HIGH
OpenSift < 1.1.3-alpha - Stored Cross-Site Scripting via Unsafe HTML Interpolation
CVSS 8.9
CVE-2026-27016 MEDIUM
LibreNMS 24.10.0-26.1.1 - Stored XSS
CVSS 5.4
CVE-2026-26953 MEDIUM
Pi-hole Web Interface 6.0-6.4.1 - Authenticated Stored HTML Injection via X-Forwarded-For Header
CVSS 5.4
CVE-2026-26952 MEDIUM
Pi-hole web_interface < 6.4.1 - Authenticated Stored HTML Injection via DNS Records Configuration
CVSS 5.4
CVE-2026-27013 HIGH
fabric.js < 7.2.0 - Stored Cross-Site Scripting via SVG Export
CVSS 7.6
CVE-2026-25940 HIGH
jspdf < 4.2.0 - Arbitrary PDF Object Injection via Acroform Module
CVSS 8.1
CVE-2026-25755 HIGH
jsPDF < 4.2.0 - Code Injection via addJS Method
CVSS 8.1
CVE-2026-25230 MEDIUM
FileRise < 3.3.0 - Authenticated HTML Injection via DOM Manipulation
CVSS 4.6
CVE-2026-25543 MEDIUM
HtmlSanitizer < 9.0.892 - Cross-Site Scripting via Template Tag
CVSS 6.1
CVE-2026-24737 HIGH
jsPDF < 4.1.0 - Arbitrary PDF Object Injection via Acroform Module
CVSS 8.1
CVE-2026-0818 MEDIUM
Thunderbird < 140.7.1 and 140.* < 140.7.1 and < 147.0.1 - Information Disclosure via CSS and Remote Content
CVSS 4.3
CVE-2026-24439 MEDIUM
Shenzhen Tenda W30E V2 <16.01.0.19(5037) - XSS
CVSS 6.5
CVE-2026-24127 MEDIUM
typemill < 2.19.2 - Reflected Cross-Site Scripting via Login Error Template
CVSS 5.4
CVE-2026-23630 MEDIUM
docmost 0.3.0-0.23.2 - Stored Cross-Site Scripting via Mermaid Diagram Rendering
CVSS 5.4
CVE-2026-22792 CRITICAL
5ire < 0.15.3 - Remote Code Execution via Unsafe HTML Rendering
CVSS 9.6
CVE-2026-23880 HIGH
OnboardLite <commit 1d32081a66f21bcf41df1ecb672490b13f6e429f - XSS
CVSS 7.3
CVE-2026-1011 MEDIUM
Altium Live < 1.1.1.39 - Stored Cross-Site Scripting via AddComment Endpoint
CVSS 6.1
CVE-2026-22712 MEDIUM
Mediawiki - ApprovedRevs Extension <1.45 - XSS
CVSS 4.3
CVE-2025-12697 LOW
GitLab 15.5-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Datadog API Credential Exposure
CVSS 2.2
CVE-2025-15312 MEDIUM
Tanium TanOS 1.8.3-1.8.3.0146 - Improper Output Sanitization
CVSS 6.6
CVE-2025-66488 MEDIUM
Discourse <3.5.4-2026.1.0 - Info Disclosure
CVSS 4.6
CVE-2025-59158 HIGH
Coolify <= 4.0.0-beta.420.6 - Authenticated Stored Cross-Site Scripting via Project Name
CVSS 8.0
CVE-2025-68460 HIGH
Roundcube Webmail < 1.5.12 and 1.6 < 1.6.12 - Information Disclosure via HTML Style Sanitizer
CVSS 7.2
Details
Vulnerabilities 446
Exploit Likelihood High