The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
122 vulnerabilities with CWE-184
CVE-2026-31992
HIGH
OpenClaw < 2026.2.23 - Allowlist Exec-Guard Bypass via env -S
CVSS 7.1
CVE-2026-22175
HIGH
OpenClaw < 2026.2.23 - Exec Approval Bypass via Unrecognized Multiplexer Shell Wrappers
CVSS 7.1
CVE-2026-32128
MEDIUM
fastgpt < 4.14.7 - Arbitrary File Write via stdout File Descriptor Remapping
CVSS 6.3
CVE-2026-28783
CRITICAL
Craft CMS <5.9.0-beta.1/4.17.0-beta.1 - RCE
CVSS 9.1
CVE-2026-28363
CRITICAL
OpenClaw <2026.2.23 - Command Injection
CVSS 9.9
CVE-2026-1773
HIGH
Hitachi Energy RTU500 Series Firmware 12.7.1-12.7.6 - Denial of Service via Invalid U-format Frame
CVSS 7.5
CVE-2026-25951
HIGH
FUXA < 1.2.11 - Authenticated Path Traversal and Remote Code Execution via Nested Traversal Sequences
CVSS 7.2
CVE-2026-22609
HIGH
fickling < 0.1.7 - Incomplete List of Disallowed Inputs in unsafe_imports()
CVSS 7.8
CVE-2026-22608
HIGH
fickling < 0.1.7 - Remote Code Execution via Unblocked ctypes and pydoc Modules
CVSS 7.8
CVE-2026-22607
HIGH
fickling <= 0.1.6 - Incomplete List of Disallowed Inputs in cProfile Module Handling
CVSS 7.8
CVE-2026-22606
HIGH
fickling < 0.1.7 - Incomplete List of Disallowed Inputs in runpy Module Handling
CVSS 7.8
CVE-2025-69277
MEDIUM
libsodium <ad3004e - Memory Corruption
CVSS 4.5
CVE-2025-67748
HIGH
fickling < 0.1.6 - Unsafe Pickle Misclassification via pty Module Import Bypass
CVSS 7.8
CVE-2025-67747
HIGH
fickling < 0.1.6 - Arbitrary Code Execution via Marshal and Types Module Bypass
CVSS 7.8
CVE-2025-67716
MEDIUM
Auth0 Next.js SDK <4.13.0 - Info Disclosure
CVSS 5.7
CVE-2025-61924
LOW
PrestaShop Checkout <4.4.1, 5.0.5 - Info Disclosure
CVSS 3.8
CVE-2025-58361
CRITICAL
promptcraft-forge-studio - Cross-Site Scripting via Incomplete URL Scheme Validation
CVSS 9.3
CVE-2025-58353
HIGH
promptcraft-forge-studio - Cross-Site Scripting via Regex Blacklist Bypass
CVSS 8.2
CVE-2025-48732
HIGH
WWBN AVideo 14.4 and dev master - Remote Code Execution via .phar File Request
CVSS 7.3
CVE-2025-24388
LOW
OTRS 7.0.x 8.0.x 2023.x 2024.x 2025.x and ((OTRS)) Community Edition 6.0.x - Authenticated Parameter Injection
CVSS 3.8
CVE-2025-1484
MEDIUM
Hitachi Energy Asset Suite 9.6.4.4-9.6.4.5 - Stored Cross-Site Scripting via Media Upload Component
CVSS 6.5
CVE-2025-46417
HIGH
Picklescan <0.0.25 - Info Disclosure
CVSS 7.5
CVE-2025-29822
HIGH
Microsoft Office OneNote - Info Disclosure
CVSS 7.8
CVE-2025-1716
CRITICAL
picklescan <0.0.21 - Code Injection
CVSS 9.8
CVE-2024-54149
HIGH
Winter CMS <1.2.7, 1.1.11, 1.0.476 - Auth Bypass
CVSS 8.4
Details
Vulnerabilities
122