CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

446 vulnerabilities with CWE-116
CVE-2025-27109 HIGH
solid-js < 1.9.4 - Cross-Site Scripting via Inlined JSX Fragment
CVSS 7.3
CVE-2025-27108 HIGH
dom-expressions < 0.39.5 - Cross-Site Scripting via Special Replacement Patterns in .replace()
CVSS 7.3
CVE-2025-24025 MEDIUM
Coolify < 4.0.0-beta.380 - Cross-Site Scripting via Tags Search Query
CVSS 6.1
CVE-2025-23207 MEDIUM
KaTeX 0.12.0-0.16.20 - Cross-Site Scripting via \htmlData Command
CVSS 6.3
CVE-2024-58266 LOW
shlex < 1.2.1 - Command Injection via Unquoted Brace and Non-Breaking Space Characters
CVSS 3.2
CVE-2024-56524 CRITICAL
Radware Cloud WAF <2025-05-07 - Auth Bypass
CVSS 9.1
CVE-2024-9606 HIGH
berriai/litellm <1.44.12 - Info Disclosure
CVSS 7.5
CVE-2024-50629 MEDIUM
Synology BeeStation OS <1.1-65374 & DSM <7.1.1-42962-7,7.2-64570-4,...
CVSS 5.3
CVE-2024-10441 CRITICAL
Synology BeeStation OS <1.1-65374 & DSM <7.2-64570-4, 7.2.1-69057-6...
CVSS 9.8
CVE-2024-49355 MEDIUM
IBM OpenPages with Watson <9.0 - Info Disclosure
CVSS 5.3
CVE-2024-56473 MEDIUM
IBM Aspera Shares 1.9.0-1.10.0 PL6 - IP Address Spoofing via Client-IP Header
CVSS 5.3
CVE-2024-56277 MEDIUM
Poll Maker < 5.5.5 - HTML Injection
CVSS 5.3
CVE-2024-52005 HIGH
Git < 2.40.4 - Terminal Control Sequence Injection via Sideband Channel
CVSS 8.8
CVE-2024-52006 HIGH
Git < 2.40.4 - Command Injection via Carriage Return Character
CVSS 7.5
CVE-2024-50349 MEDIUM
Git < 2.40.4 - Terminal Credential Prompt Spoofing via ANSI Escape Sequences
CVSS 4.7
CVE-2024-52891 MEDIUM
IBM Concert Software <1.0.4 - Info Disclosure
CVSS 5.4
CVE-2024-9427 MEDIUM
Koji 1.35.0 - Reflected Cross-Site Scripting via Unsanitized Input
CVSS 5.4
CVE-2024-55663 CRITICAL
XWiki Platform <13.10.5-14.3-rc-1 - SQL Injection
CVSS 9.8
CVE-2024-46547 HIGH
Romain Bourdon Wampserver - Info Disclosure
CVSS 7.5
CVE-2024-46901 LOW
Apache Subversion <1.14.4 - Info Disclosure
CVSS 3.1
CVE-2024-42332 LOW
Zabbix 6.0.0-6.0.35 - SNMP Trap Log Forgery via Malformed Trap Data
CVSS 3.7
CVE-2024-10006 HIGH
Consul 1.4.1-1.20.0 and 1.9.0-1.15.14 - HTTP Header Bypass via L7 Traffic Intentions
CVSS 8.3
CVE-2024-47549 HIGH
Sharp/Toshiba Tec MFPs - XSS
CVSS 7.4
CVE-2024-47224 MEDIUM
Mitel MiCollab <9.8.1.201 - CRLF Injection
CVSS 6.5
CVE-2024-40088 MEDIUM
Vilo 5 Mesh WiFi System <= 5.16.1.33 - Path Traversal
CVSS 5.3
Details
Vulnerabilities 446
Exploit Likelihood High