CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2026-32754
CRITICAL
FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})
CVSS 9.3
CVE-2026-33301
HIGH
OpenEMR has arbitrary image file read via PDF generator
CVSS 8.1
CVE-2026-31898
HIGH
jsPDF <4.2.1 createAnnotation color - PDF Object Injection
CVSS 8.1
CVE-2026-28499
MEDIUM
Vapor LeafKit < 1.14.2 - Collection Value Cross-Site Scripting
CVSS 6.1
CVE-2026-3644
HIGH
Incomplete control character validation in http.cookies
CVSS 7.5
CVE-2026-31859
MEDIUM
Craft CMS 4.15.3-4.17.3 - Reflected Cross-Site Scripting via Unsanitized Return URL
CVSS 6.1
CVE-2026-28350
MEDIUM
lxml_html_clean <0.4.4 - Auth Bypass
CVSS 6.1
CVE-2026-28348
MEDIUM
lxml_html_clean < 0.4.4 - Cross-Site Scripting via CSS Unicode Escape Sequence Bypass
CVSS 6.1
CVE-2026-27812
CRITICAL
sub2api < 0.1.85 - Password Reset Poisoning via Host Header Manipulation
CVSS 9.1
CVE-2026-21443
MEDIUM
OpenEMR < 8.0.0 - Cross-Site Scripting via Unescaped Translation Function Output
CVSS 6.1
CVE-2026-27512
MEDIUM
Tenda F3 Firmware < 12.01.01.55_multi - Reflected Script Execution via Missing nosniff Header
CVSS 6.1
CVE-2026-27469
MEDIUM
Isso < 0.13.2 - Stored Cross-Site Scripting via Website and Author Comment Fields
CVSS 6.1
CVE-2026-27169
HIGH
OpenSift < 1.1.3-alpha - Stored Cross-Site Scripting via Unsafe HTML Interpolation
CVSS 8.9
CVE-2026-27016
MEDIUM
LibreNMS 24.10.0-26.1.1 - Stored XSS
CVSS 5.4
CVE-2026-26953
MEDIUM
Pi-hole Web Interface 6.0-6.4.1 - Authenticated Stored HTML Injection via X-Forwarded-For Header
CVSS 5.4
CVE-2026-26952
MEDIUM
Pi-hole web_interface < 6.4.1 - Authenticated Stored HTML Injection via DNS Records Configuration
CVSS 5.4
CVE-2026-27013
HIGH
fabric.js < 7.2.0 - Stored Cross-Site Scripting via SVG Export
CVSS 7.6
CVE-2026-25940
HIGH
jspdf < 4.2.0 - Arbitrary PDF Object Injection via Acroform Module
CVSS 8.1
CVE-2026-25755
HIGH
jsPDF < 4.2.0 - Code Injection via addJS Method
CVSS 8.1
CVE-2026-25230
MEDIUM
FileRise < 3.3.0 - Authenticated HTML Injection via DOM Manipulation
CVSS 4.6
CVE-2026-25543
MEDIUM
HtmlSanitizer < 9.0.892 - Cross-Site Scripting via Template Tag
CVSS 6.1
CVE-2026-24737
HIGH
jsPDF < 4.1.0 - Arbitrary PDF Object Injection via Acroform Module
CVSS 8.1
CVE-2026-0818
MEDIUM
Thunderbird < 140.7.1 and 140.* < 140.7.1 and < 147.0.1 - Information Disclosure via CSS and Remote Content
CVSS 4.3
CVE-2026-24439
MEDIUM
Shenzhen Tenda W30E V2 <16.01.0.19(5037) - XSS
CVSS 6.5
CVE-2026-24127
MEDIUM
typemill < 2.19.2 - Reflected Cross-Site Scripting via Login Error Template
CVSS 5.4
Details
Vulnerabilities
482
Exploit Likelihood
High