VYPR

CWE-116

Improper Encoding or Escaping of Output

ClassDraftLikelihood: High

Description

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (510)

page 13 of 26
  • CVE-2022-29251HigMay 25, 2022
    risk 0.41cvss 7.4epss 0.01

    XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the `FlamingoThemesCode.WebHomeSheet` wiki page related to the…

  • CVE-2026-25932HigApr 6, 2026
    risk 0.40cvss 7.2epss 0.00

    GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

  • CVE-2026-32986MedMar 20, 2026
    risk 0.40cvss 6.1epss 0.00

    Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject malicious scripts by exploiting improper sanitization of user-supplied input in Atom feed XML elements. Attackers can embed unescaped payloads in parameters…

  • CVE-2026-27512MedFeb 23, 2026
    risk 0.40cvss 6.1epss 0.00

    Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the administrative interface. Responses omit the X-Content-Type-Options: nosniff header and include attacker-influenced content that can be reflected into the…

  • CVE-2026-1011MedJan 16, 2026
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interface applies HTML escaping, the backend accepts and stores arbitrary HTML and JavaScript supplied via…

  • CVE-2025-63785MedNov 7, 2025
    risk 0.40cvss 6.1epss 0.00

    A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input is not properly sanitized before being directly injected into the DOM via innerHTML when editing a…

  • CVE-2021-47694MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.00

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject…

  • CVE-2025-11712MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.00

    A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header.…

  • CVE-2025-47280MedMay 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 and 15.1.2, the 'Send email' workflow does not HTML encode the user-provided field values in the sent email message, making any…

  • CVE-2025-27109HigFeb 21, 2025
    risk 0.40cvss 7.3epss 0.00

    solid-js is a declarative, efficient, and flexible JavaScript library for building user interfaces. In affected versions Inserts/JSX expressions inside illegal inlined JSX fragments lacked escaping, allowing user input to be rendered as HTML when put directly inside JSX…

  • CVE-2025-27108HigFeb 21, 2025
    risk 0.40cvss 7.3epss 0.00

    dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. In affected versions the use of javascript's `.replace()` opens up to potential Cross-site Scripting (XSS) vulnerabilities with the special replacement patterns beginning with `$`. Particularly, when the…

  • CVE-2025-24025MedJan 24, 2025
    risk 0.40cvss 6.1epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on the error modal, which leads…

  • CVE-2024-0233MedJan 16, 2024
    risk 0.40cvss 6.1epss 0.00

    The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not properly sanitise and escape a parameter before outputting it back in pages, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2022-31458MedJul 25, 2023
    risk 0.40cvss 6.1epss 0.00

    RTX TRAP v1.0 was discovered to be vulnerable to host header poisoning.

  • CVE-2023-3668HigJul 14, 2023
    risk 0.40cvss 7.2epss 0.01

    Improper Encoding or Escaping of Output in GitHub repository froxlor/froxlor prior to 2.0.21.

  • CVE-2022-0421MedNov 21, 2022
    risk 0.40cvss 6.1epss 0.01

    The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of…

  • CVE-2022-2241MedAug 1, 2022
    risk 0.40cvss 6.1epss 0.01

    The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. Furthermore, due to the lack of validation, sanitisation and…

  • CVE-2022-22734MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does not sanitise and escape Quotes. As a result, attacker could make a logged in admin create or edit arbitrary quote, and put Cross-Site Scripting payloads in them

  • CVE-2021-43106MedFeb 14, 2022
    risk 0.40cvss 6.1epss 0.01

    A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.33.3 F38 and FIMI 4.2.19.4 25.The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header…

  • CVE-2022-0220MedFeb 1, 2022
    risk 0.40cvss 6.1epss 0.02

    The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be…