CWE-117
Medium likelihoodImproper Output Neutralization for Logs
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
102 vulnerabilities with CWE-117
CVE-2025-59476
MEDIUM
Jenkins < 2.516.3 and < 2.528 - Log Forgery via Line Break Injection
CVSS 5.3
CVE-2025-54813
HIGH
Apache Log4cxx <1.5.0 - Info Disclosure
CVSS 7.5
CVE-2025-54812
MEDIUM
Apache Log4cxx < 1.5.0 - Cross-Site Scripting in HTMLLayout Logger Name
CVSS 5.4
CVE-2025-54389
MEDIUM
Advanced Intrusion Detection Environment < 0.19.2 - Log Tampering via Terminal Escape Sequences
CVSS 6.2
CVE-2025-54656
MEDIUM
Apache Struts Extras <2 - Info Disclosure
CVSS 6.5
CVE-2025-49846
MEDIUM
Wire iOS <3.124.1 - Info Disclosure
CVE-2025-48432
MEDIUM
Django <5.2.3-4.2.23 - Info Disclosure
CVSS 4.0
CVE-2025-3942
MEDIUM
Tridium Niagara <4.14.2-4.15.1-4.10.11 - Input Data Manipulation
CVSS 4.3
CVE-2025-41429
MEDIUM
a-blog cms 2.8.0-2.8.84 - Unauthenticated Session Hijacking via Log Injection
CVSS 4.8
CVE-2025-36625
MEDIUM
Nessus < 10.8.4 - Unauthenticated Log Injection via HTTP Request Manipulation
CVSS 4.3
CVE-2025-25294
MEDIUM
Envoy Gateway <1.2.7-1.3.1 - Log Injection
CVSS 5.3
CVE-2025-27111
HIGH
Rack <2.2.12, <3.0.13, <3.1.11 - Log Injection
CVSS 7.5
CVE-2025-23405
MEDIUM
Unauthenticated Log Effects - Info Disclosure
CVSS 5.3
CVE-2025-25184
MEDIUM
Rack <2.2.11, 3.0.12, 3.1.10 - Info Disclosure
CVSS 6.5
CVE-2025-0754
MEDIUM
OpenShift Service Mesh 2.6.3-2.5.6 - Log Injection
CVSS 4.3
CVE-2024-13949
MEDIUM
ABB ASPECT-Enterprise NEXUS Series MATRIX Series <= 3.* - Disk Overutilization via Large Content Injection
CVSS 6.8
CVE-2024-52962
MEDIUM
FortiAnalyzer <7.6.1 - Info Disclosure
CVSS 5.3
CVE-2024-9606
HIGH
berriai/litellm <1.44.12 - Info Disclosure
CVSS 7.5
CVE-2024-12580
MEDIUM
danny-avila/librechat <0.7.6 - Code Injection
CVSS 5.3
CVE-2024-49355
MEDIUM
IBM OpenPages with Watson <9.0 - Info Disclosure
CVSS 5.3
CVE-2024-56473
MEDIUM
IBM Aspera Shares 1.9.0-1.10.0 PL6 - IP Address Spoofing via Client-IP Header
CVSS 5.3
CVE-2024-35150
MEDIUM
IBM Maximo Application Suite <9.1.0 - Info Disclosure
CVSS 5.3
CVE-2024-52891
MEDIUM
IBM Concert Software <1.0.4 - Info Disclosure
CVSS 5.4
CVE-2024-7696
MEDIUM
AXIS Camera Station Pro < 6.5.35848 - Authenticated Denial of Service via Audit Log Tampering
CVSS 6.3
CVE-2024-9026
LOW
PHP <8.1.30, <8.2.24, <8.3.12 - Info Disclosure
CVSS 3.3
Details
Vulnerabilities
102
Exploit Likelihood
Medium