The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as control elements or syntactic markers when they are sent to a downstream component.
13 vulnerabilities with CWE-138
CVE-2026-26129
HIGH
M365 Copilot Information Disclosure Vulnerability
CVSS 7.5
CVE-2026-32178
HIGH
.NET Spoofing Vulnerability
CVSS 7.5
CVE-2026-20009
MEDIUM
Cisco Secure Firewall ASA - Auth Bypass
CVSS 5.3
CVE-2025-48939
MEDIUM
tarteaucitron.js <1.22.0 - Code Injection
CVSS 4.2
CVE-2025-5878
HIGH
ESAPI esapi-java-legacy - SQL Injection
CVSS 7.3
CVE-2024-51500
MEDIUM
meshtastic_firmware < 2.5.6 - Denial of Service via Broadcast Address Spoofing
CVSS 5.3
CVE-2024-38133
HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2023-7012
CRITICAL
Google Chrome <117.0.5938.62 - Sandbox Escape
CVSS 9.6
CVE-2023-42117
CRITICAL
Exim < 4.96.2 - Unauthenticated Remote Code Execution via SMTP Service
CVSS 9.8
CVE-2023-22288
MEDIUM
Tribe29 Checkmk <=2.1.0p23, <=2.0.0p34 & 1.6.0 - Code Injection
CVSS 4.1
CVE-2022-2429
MEDIUM
Ultimate SMS Notifications for WooCommerce <1.4.1 - Code Injection
CVSS 6.5
CVE-2022-0024
HIGH
Palo Alto Networks PAN-OS <8.1.23, <9.0 - Privilege Escalation
CVSS 7.2
CVE-2016-0750
MEDIUM
Infinispan <9.1.0.Final - Code Injection
CVSS 4.2
Details
Vulnerabilities
13