CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
482 vulnerabilities with CWE-116
CVE-2026-23630
MEDIUM
docmost 0.3.0-0.23.2 - Stored Cross-Site Scripting via Mermaid Diagram Rendering
CVSS 5.4
CVE-2026-22792
CRITICAL
5ire < 0.15.3 - Remote Code Execution via Unsafe HTML Rendering
CVSS 9.6
CVE-2026-23880
HIGH
OnboardLite <commit 1d32081a66f21bcf41df1ecb672490b13f6e429f - XSS
CVSS 7.3
CVE-2026-1011
MEDIUM
Altium Live < 1.1.1.39 - Stored Cross-Site Scripting via AddComment Endpoint
CVSS 6.1
CVE-2026-22712
MEDIUM
Mediawiki - ApprovedRevs Extension <1.45 - XSS
CVSS 4.3
CVE-2025-51677
CRITICAL
openRISC OR1200 commit 83ac6b - Logic Mismatch and Unexpected Behavior via RTL-Netlist Output Port Mismatch
CVSS 9.1
CVE-2025-12697
LOW
GitLab 15.5-18.7.5, 18.8-18.8.5, 18.9-18.9.1 - Authenticated Datadog API Credential Exposure
CVSS 2.2
CVE-2025-15312
MEDIUM
Tanium TanOS 1.8.3-1.8.3.0146 - Improper Output Sanitization
CVSS 6.6
CVE-2025-66488
MEDIUM
Discourse <3.5.4-2026.1.0 - Info Disclosure
CVSS 4.6
CVE-2025-59158
HIGH
Coolify <= 4.0.0-beta.420.6 - Authenticated Stored Cross-Site Scripting via Project Name
CVSS 8.0
CVE-2025-68460
HIGH
Roundcube Webmail < 1.5.12 and 1.6 < 1.6.12 - Information Disclosure via HTML Style Sanitizer
CVSS 7.2
CVE-2025-12734
LOW
GitLab 15.6-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Authenticated Cross-Site Scripting via Merge Request Title
CVSS 3.5
CVE-2025-8405
HIGH
GitLab CE/EE <18.4.6-18.6.2 - Privilege Escalation
CVSS 7.7
CVE-2025-42896
MEDIUM
SAP BusinessObjects BI Platform - Login Error URL Server-Side Request Forgery
CVSS 5.4
CVE-2025-66548
LOW
Nextcloud Deck <1.12.7, 1.14.4, 1.15.1 - Info Disclosure
CVSS 3.3
CVE-2025-9127
MEDIUM
Portworx 3.1.1-3.1.8 - Sensitive Information Exposure via Logging
CVSS 5.5
CVE-2025-13742
MEDIUM
pretix < 2025.7.2 - Email Content Spoofing via Attendee Name Placeholder
CVSS 6.1
CVE-2025-64325
CRITICAL
Emby Server <4.8.1.0-4.9.0.0-beta - Info Disclosure
CVSS 9.0
CVE-2025-40547
CRITICAL
SolarWinds Serv-U < 15.5.3 - Authenticated Remote Code Execution
CVSS 9.1
CVE-2025-11085
HIGH
FactoryTalk DataMosaix Private Cloud 7.11-8.00 - Stored Cross-Site Scripting
CVE-2025-63785
MEDIUM
Onlook 0.2.32 - DOM-based Cross-Site Scripting in Text Editor via innerHTML Injection
CVSS 6.1
CVE-2025-61084
HIGH
MDaemon Mail Server 23.5.2 - Info Disclosure
CVSS 7.1
CVE-2025-46583
MEDIUM
ZTE MC889A Pro - Denial of Service via Short Message Service Interface
CVSS 5.3
CVE-2025-11713
HIGH
Firefox <144, Firefox ESR <140.4, Thunderbird <144, Thunderbird <14...
CVSS 8.1
CVE-2025-11712
MEDIUM
Firefox < 144.0 and 140.4-140.* - Cross-Site Scripting via OBJECT Tag Type Attribute
CVSS 6.1
Details
Vulnerabilities
482
Exploit Likelihood
High