CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2026-23630 MEDIUM
docmost 0.3.0-0.23.2 - Stored Cross-Site Scripting via Mermaid Diagram Rendering
CVSS 5.4
CVE-2026-22792 CRITICAL
5ire < 0.15.3 - Remote Code Execution via Unsafe HTML Rendering
CVSS 9.6
CVE-2026-23880 HIGH
OnboardLite <commit 1d32081a66f21bcf41df1ecb672490b13f6e429f - XSS
CVSS 7.3
CVE-2026-1011 MEDIUM
Altium Live < 1.1.1.39 - Stored Cross-Site Scripting via AddComment Endpoint
CVSS 6.1
CVE-2026-22712 MEDIUM
Mediawiki - ApprovedRevs Extension <1.45 - XSS
CVSS 4.3
CVE-2025-51677 CRITICAL
openRISC OR1200 commit 83ac6b - Logic Mismatch and Unexpected Behavior via RTL-Netlist Output Port Mismatch
CVSS 9.1
CVE-2025-12697 LOW
GitLab 15.5-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Datadog API Credential Exposure
CVSS 2.2
CVE-2025-15312 MEDIUM
Tanium TanOS 1.8.3-1.8.3.0146 - Improper Output Sanitization
CVSS 6.6
CVE-2025-66488 MEDIUM
Discourse <3.5.4-2026.1.0 - Info Disclosure
CVSS 4.6
CVE-2025-59158 HIGH
Coolify <= 4.0.0-beta.420.6 - Authenticated Stored Cross-Site Scripting via Project Name
CVSS 8.0
CVE-2025-68460 HIGH
Roundcube Webmail < 1.5.12 and 1.6 < 1.6.12 - Information Disclosure via HTML Style Sanitizer
CVSS 7.2
CVE-2025-12734 LOW
GitLab 15.6-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Authenticated Cross-Site Scripting via Merge Request Title
CVSS 3.5
CVE-2025-8405 HIGH
GitLab CE/EE <18.4.6-18.6.2 - Privilege Escalation
CVSS 7.7
CVE-2025-42896 MEDIUM
SAP BusinessObjects BI Platform - Login Error URL Server-Side Request Forgery
CVSS 5.4
CVE-2025-66548 LOW
Nextcloud Deck <1.12.7, 1.14.4, 1.15.1 - Info Disclosure
CVSS 3.3
CVE-2025-9127 MEDIUM
Portworx 3.1.1-3.1.8 - Sensitive Information Exposure via Logging
CVSS 5.5
CVE-2025-13742 MEDIUM
pretix < 2025.7.2 - Email Content Spoofing via Attendee Name Placeholder
CVSS 6.1
CVE-2025-64325 CRITICAL
Emby Server <4.8.1.0-4.9.0.0-beta - Info Disclosure
CVSS 9.0
CVE-2025-40547 CRITICAL
SolarWinds Serv-U < 15.5.3 - Authenticated Remote Code Execution
CVSS 9.1
CVE-2025-11085 HIGH
FactoryTalk DataMosaix Private Cloud 7.11-8.00 - Stored Cross-Site Scripting
CVE-2025-63785 MEDIUM
Onlook 0.2.32 - DOM-based Cross-Site Scripting in Text Editor via innerHTML Injection
CVSS 6.1
CVE-2025-61084 HIGH
MDaemon Mail Server 23.5.2 - Info Disclosure
CVSS 7.1
CVE-2025-46583 MEDIUM
ZTE MC889A Pro - Denial of Service via Short Message Service Interface
CVSS 5.3
CVE-2025-11713 HIGH
Firefox <144, Firefox ESR <140.4, Thunderbird <144, Thunderbird <14...
CVSS 8.1
CVE-2025-11712 MEDIUM
Firefox < 144.0 and 140.4-140.* - Cross-Site Scripting via OBJECT Tag Type Attribute
CVSS 6.1
Details
Vulnerabilities 482
Exploit Likelihood High