The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
70 vulnerabilities with CWE-184
CVE-2026-28391
CRITICAL
OpenClaw <2026.2.2 - Command Injection
CVSS 9.8
CVE-2026-28783
CRITICAL
Craft CMS <5.9.0-beta.1/4.17.0-beta.1 - RCE
CVSS 9.1
CVE-2026-28363
CRITICAL
OpenClaw <2026.2.23 - Command Injection
CVSS 9.9
CVE-2026-1773
HIGH
IEC 60870-5-104 - DoS
CVSS 7.5
CVE-2026-25951
HIGH
Frangoteam Fuxa < 1.2.11 - Path Traversal
CVSS 7.2
CVE-2026-22609
HIGH
Fickling <0.1.7 - Code Injection
CVSS 7.8
CVE-2026-22608
HIGH
Fickling <0.1.7 - RCE
CVSS 7.8
CVE-2026-22607
HIGH
Fickling <0.1.6 - Code Injection
CVSS 7.8
CVE-2026-22606
HIGH
Fickling <0.1.6 - Code Injection
CVSS 7.8
CVE-2025-69277
MEDIUM
libsodium <ad3004e - Memory Corruption
CVSS 4.5
CVE-2025-67748
HIGH
Trailofbits Fickling < 0.1.6 - Insecure Deserialization
CVSS 7.8
CVE-2025-67747
HIGH
Fickling <0.1.6 - Code Injection
CVSS 7.8
CVE-2025-67716
MEDIUM
Auth0 Next.js SDK <4.13.0 - Info Disclosure
CVSS 5.7
CVE-2025-61924
LOW
PrestaShop Checkout <4.4.1, 5.0.5 - Info Disclosure
CVSS 3.8
CVE-2022-50238
HIGH
Microsoft - Info Disclosure
CVSS 7.4
CVE-2025-58361
CRITICAL
Promptcraft Forge Studio - XSS
CVSS 9.3
CVE-2025-58353
HIGH
Promptcraft Forge Studio - XSS
CVSS 8.2
CVE-2025-48732
HIGH
WWBN AVideo <14.4 - RCE
CVSS 7.3
CVE-2025-24388
LOW
OTRS <8 - Command Injection
CVSS 3.8
CVE-2025-1484
MEDIUM
Asset Suite - XSS
CVSS 6.5
CVE-2025-46417
HIGH
Picklescan <0.0.25 - Info Disclosure
CVSS 7.5
CVE-2025-29822
HIGH
Microsoft Office OneNote - Info Disclosure
CVSS 7.8
CVE-2025-1716
CRITICAL
picklescan <0.0.21 - Code Injection
CVSS 9.8
CVE-2024-54149
HIGH
Winter CMS <1.2.7, 1.1.11, 1.0.476 - Auth Bypass
CVSS 8.4
CVE-2024-52595
HIGH
Fedoralovespython Lxml Html Clean < 0.4.0 - XSS
CVSS 7.7
Details
Vulnerabilities
70