CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2025-61912 MEDIUM
python-ldap < 3.4.5 - Denial of Service via Incorrect Null Byte Escaping in ldap.dn.escape_dn_chars()
CVSS 5.3
CVE-2025-55903 HIGH
Perfex CRM 3.3.1 - HTML Injection in Estimate Module Bill To Address Field
CVSS 8.3
CVE-2025-61773 HIGH
pyload-ng < 0.5.0b3.dev91 - Cross-Site Scripting via Captcha Script Endpoint and Click'N'Load Blueprint
CVSS 8.1
CVE-2025-0607 MEDIUM
Logo Cloud < 2.57 - Phishing via Improper Output Encoding
CVSS 4.3
CVE-2025-60787 HIGH
MotionEye <= 0.43.1b4 - Authenticated Configuration Command Injection
CVSS 7.2
CVE-2025-59936 CRITICAL
get-jwks < 11.0.2 - JWKS Cache Poisoning via Issuer Validation Bypass
CVSS 9.4
CVE-2025-57880 MEDIUM
BlueSpice 5.0-5.1.1 - Cross-Site Scripting in BlueSpiceWhoIsOnline Extension
CVSS 5.4
CVE-2025-48007 MEDIUM
BlueSpice 5.0-5.1.1 - Cross-Site Scripting in BlueSpiceAvatars Extension
CVSS 6.4
CVE-2025-46703 MEDIUM
BlueSpice 5.0-5.1.1 - Cross-Site Scripting in AtMentions Extension
CVSS 6.4
CVE-2025-8276 MEDIUM
Patika Global Technologies HumanSuite <53.21.0 - XSS
CVSS 4.3
CVE-2025-55730 CRITICAL
xwiki-pro-macros 1.0-1.26.4 - Remote Code Execution via Confluence Paste Code Macro Title
CVSS 10.0
CVE-2025-55729 CRITICAL
xwiki-pro-macros 1.0-1.26.4 - Remote Code Execution via ConfluenceLayoutSection Macro
CVSS 10.0
CVE-2025-56266 CRITICAL
Avigilon Access Control Manager 7.10.0.20 - Remote Code Execution via Host Header Injection
CVSS 9.8
CVE-2025-0083 MEDIUM
Multiple Locations - Info Disclosure
CVSS 4.0
CVE-2025-34141 MEDIUM
ETQ Reliance CG (legacy) < SE.2025.1 - Reflected Cross-Site Scripting in SQLConverterServlet
CVE-2025-6429 MEDIUM
Firefox < 140.0 and 128.12-128.* - URL Parsing Bypass via Embed Tag
CVSS 6.5
CVE-2025-49013 CRITICAL
WilderForge - Remote Code Execution via GitHub Actions Workflow Injection
CVSS 9.9
CVE-2025-48062 HIGH
Discourse <3.4.4, <3.5.0.beta5, <3.5.0.beta6-dev - XSS
CVSS 7.1
CVE-2025-25029 MEDIUM
IBM Security Guardium 12.0 - Info Disclosure
CVSS 4.9
CVE-2025-5271 MEDIUM
Firefox < 139.0 - Content Injection via Devtools Response Preview
CVSS 6.5
CVE-2025-3942 MEDIUM
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Input Data Manipulation
CVSS 4.3
CVE-2025-1308 HIGH
Pure Storage PX Backup 1.0.0-2.5.9, 2.7.0-2.7.2, 2.8.0 - Information Exposure via Logging
CVE-2025-47280 MEDIUM
Umbraco Forms <13.4.2-15.1.2 - Info Disclosure
CVSS 6.1
CVE-2025-46340 HIGH
Misskey 12.0.0-2025.4.1 - CSS Injection via UrlPreviewService and MkUrlPreview
CVSS 7.2
CVE-2025-32974 CRITICAL
XWiki 15.9-15.10.7 and 16.0.0-16.1.0 - Privilege Escalation via TextArea Default Content Type
CVSS 9.0
Details
Vulnerabilities 482
Exploit Likelihood High