CWE-184

Incomplete List of Disallowed Inputs

Parent: CWE-693 - Protection Mechanism Failure

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

161 vulnerabilities with CWE-184
CVE-2026-34430 HIGH
ByteDance DeerFlow LocalSandboxProvider Host Bash Escape
CVSS 8.8
CVE-2026-33628 MEDIUM
Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items
CVSS 5.4
CVE-2026-33396 CRITICAL
OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
CVSS 9.9
CVE-2026-4509 MEDIUM
PbootCMS File Upload file.php incomplete blacklist
CVSS 6.3
CVE-2026-33139 HIGH
PySpector: Plugin Sandbox Bypass leads to Arbitrary Code Execution
CVSS 7.8
CVE-2026-32940 CRITICAL
SiYuan <3.6.1 getDynamicIcon - Cross-Site Scripting
CVSS 9.3
CVE-2026-32022 MEDIUM
OpenClaw < 2026.2.21 - Arbitrary File Read via grep -e Flag Policy Bypass
CVSS 6.5
CVE-2026-32017 HIGH
OpenClaw < 2026.2.19 - Arbitrary File Write via Short-Option Bypass in exec Allowlist
CVSS 7.1
CVE-2026-32747 MEDIUM
SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets
CVSS 6.8
CVE-2026-31993 MEDIUM
OpenClaw < 2026.2.22 - Allowlist Parsing Mismatch in system.run Shell Chains
CVSS 4.8
CVE-2026-31992 HIGH
OpenClaw < 2026.2.23 - Allowlist Exec-Guard Bypass via env -S
CVSS 7.1
CVE-2026-22175 HIGH
OpenClaw < 2026.2.23 - Exec Approval Bypass via Unrecognized Multiplexer Shell Wrappers
CVSS 7.1
CVE-2026-32128 MEDIUM
fastgpt < 4.14.7 - Arbitrary File Write via stdout File Descriptor Remapping
CVSS 6.3
CVE-2026-28783 CRITICAL
Craft CMS <5.9.0-beta.1/4.17.0-beta.1 - RCE
CVSS 9.1
CVE-2026-28363 CRITICAL
OpenClaw <2026.2.23 - Command Injection
CVSS 9.9
CVE-2026-1773 HIGH
Hitachi Energy RTU500 Series Firmware 12.7.1-12.7.6 - Denial of Service via Invalid U-format Frame
CVSS 7.5
CVE-2026-25951 HIGH
FUXA < 1.2.11 - Authenticated Path Traversal and Remote Code Execution via Nested Traversal Sequences
CVSS 7.2
CVE-2026-22609 HIGH
fickling < 0.1.7 - Incomplete List of Disallowed Inputs in unsafe_imports()
CVSS 7.8
CVE-2026-22608 HIGH
fickling < 0.1.7 - Remote Code Execution via Unblocked ctypes and pydoc Modules
CVSS 7.8
CVE-2026-22607 HIGH
fickling <= 0.1.6 - Incomplete List of Disallowed Inputs in cProfile Module Handling
CVSS 7.8
CVE-2026-22606 HIGH
fickling < 0.1.7 - Incomplete List of Disallowed Inputs in runpy Module Handling
CVSS 7.8
CVE-2025-71355 HIGH
Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass
CVE-2025-71351 HIGH
picklescan - Remote Code Execution via timeit.timeit() Detection Bypass
CVE-2025-71323 CRITICAL
picklescan - Remote Code Execution via Unblocked ctypes Module
CVSS 9.8
CVE-2025-71320 CRITICAL
picklescan - Remote Code Execution via Incomplete Disallowed Inputs
CVSS 9.8
Details
Vulnerabilities 161