CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2025-24338 HIGH
Bosch Rexroth ctrlX OS <2.6.0 Authenticated Stored XSS via Manages App Data
CVSS 7.1
CVE-2025-46347 CRITICAL
YesWiki < 4.5.4 - Remote Code Execution via Arbitrary File Write
CVSS 9.8
CVE-2025-4084 MEDIUM
Firefox <128.10 - Local Code Execution
CVSS 5.7
CVE-2025-31651 CRITICAL
Apache Tomcat 9.0.0-9.0.102, 10.1.0-M1-10.1.39, 11.0.0-M1-11.0.5 - Security Constraint Bypass
CVSS 9.8
CVE-2025-23377 MEDIUM
Dell PowerProtect Data Manager Reporting <19.18 - XSS
CVSS 4.2
CVE-2025-32078 MEDIUM
Mediawiki - Version Compare Ext <1.43 - XSS
CVE-2025-32074 MEDIUM
Mediawiki - Confirm Account Ext <1.39-1.43 - XSS
CVSS 5.4
CVE-2025-32072 MEDIUM
The Wikimedia Foundation Mediawiki Core - Feed Utils <1.44 - Code I...
CVE-2025-30657 MEDIUM
Juniper Junos OS DoS via Malformed BGP Update Message
CVSS 5.3
CVE-2025-30345 LOW
OpenSlides < 4.2.5 - Cross-Site Scripting via Chat Group Name
CVSS 3.5
CVE-2025-1795 LOW
CPython Email Header Injection via Address List Folding
CVE-2025-27109 HIGH
solid-js < 1.9.4 - Cross-Site Scripting via Inlined JSX Fragment
CVSS 7.3
CVE-2025-27108 HIGH
dom-expressions < 0.39.5 - Cross-Site Scripting via Special Replacement Patterns in .replace()
CVSS 7.3
CVE-2025-24025 MEDIUM
Coolify < 4.0.0-beta.380 - Cross-Site Scripting via Tags Search Query
CVSS 6.1
CVE-2025-23207 MEDIUM
KaTeX 0.12.0-0.16.20 - Cross-Site Scripting via \htmlData Command
CVSS 6.3
CVE-2024-58266 LOW
shlex < 1.2.1 - Command Injection via Unquoted Brace and Non-Breaking Space Characters
CVSS 3.2
CVE-2024-56524 CRITICAL
Radware Cloud WAF <2025-05-07 - Auth Bypass
CVSS 9.1
CVE-2024-9606 HIGH
berriai/litellm <1.44.12 - Info Disclosure
CVSS 7.5
CVE-2024-50629 MEDIUM
Synology BeeStation OS <1.1-65374 & DSM <7.1.1-42962-7,7.2-64570-4,...
CVSS 5.3
CVE-2024-10441 CRITICAL
Synology BeeStation OS <1.1-65374 & DSM <7.2-64570-4, 7.2.1-69057-6...
CVSS 9.8
CVE-2024-49355 MEDIUM
IBM OpenPages with Watson <9.0 - Info Disclosure
CVSS 5.3
CVE-2024-56473 MEDIUM
IBM Aspera Shares 1.9.0-1.10.0 PL6 - IP Address Spoofing via Client-IP Header
CVSS 5.3
CVE-2024-56277 MEDIUM
Poll Maker < 5.5.5 - HTML Injection
CVSS 5.3
CVE-2024-52005 HIGH
Git < 2.40.4 - Terminal Control Sequence Injection via Sideband Channel
CVSS 8.8
CVE-2024-52006 HIGH
Git < 2.40.4 - Command Injection via Carriage Return Character
CVSS 7.5
Details
Vulnerabilities 482
Exploit Likelihood High