VYPR

CWE-116

Improper Encoding or Escaping of Output

ClassDraftLikelihood: High

Description

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (510)

page 15 of 26
  • CVE-2025-57665MedSep 9, 2025
    risk 0.35cvss 6.4epss 0.00

    Element Plus Link component (el-link) through 2.10.6 implements insufficient input validation for the href attribute, creating a security abstraction gap that obscures URL-based attack vectors. The component passes user-controlled href values directly to underlying anchor…

  • CVE-2021-25262MedMay 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.

  • CVE-2025-32074MedApr 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Confirm Account Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Confirm Account Extension: from 1.39 through 1.43.

  • CVE-2023-35894MedMar 7, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or…

  • CVE-2024-52891MedJan 7, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious information or obtain information from log files due to improper log neutralization.

  • CVE-2024-9427MedDec 24, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the…

  • CVE-2024-40088MedOct 21, 2024
    risk 0.35cvss 5.3epss 0.01

    A Directory Traversal vulnerability in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers to enumerate the existence and length of any file in the filesystem by placing malicious payloads in the path of any HTTP request.

  • CVE-2023-26289MedJul 30, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session…

  • CVE-2024-39682MedJul 18, 2024
    risk 0.35cvss 6.4epss 0.00

    Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with…

  • CVE-2024-29894MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.01

    Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js…

  • CVE-2022-22399MedMar 5, 2024
    risk 0.35cvss 5.4epss 0.00

    IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or…

  • CVE-2023-4393MedOct 30, 2023
    risk 0.35cvss 5.4epss 0.00

    HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.

  • CVE-2023-5654MedOct 19, 2023
    risk 0.35cvss 6.5epss 0.00

    The React Developer Tools extension registers a message listener with window.addEventListener('message', ) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received…

  • CVE-2022-45102MedFeb 1, 2023
    risk 0.35cvss 5.4epss 0.00

    Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary \u2018Host\u2019 header values to poison a web cache or trigger…

  • CVE-2022-43543MedDec 21, 2022
    risk 0.35cvss 5.4epss 0.00

    KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handling of Unicode control characters. +Message App displays text unprocessed, even when control characters are contained, and the text is shown based on Unicode…

  • CVE-2021-38997MedDec 12, 2022
    risk 0.35cvss 5.4epss 0.00

    IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through 2018.4.1.19 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the…

  • CVE-2022-3941MedNov 11, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in Activity Log Plugin and classified as critical. This vulnerability affects unknown code of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutralization for logs. The attack can be…

  • CVE-2022-32549MedJun 22, 2022
    risk 0.35cvss 5.3epss 0.02

    Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files.

  • CVE-2022-30966MedMay 17, 2022
    risk 0.35cvss 5.4epss 0.01

    Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-0450MedMar 28, 2022
    risk 0.35cvss 5.4epss 0.01

    The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu…