VYPR

CWE-116

Improper Encoding or Escaping of Output

ClassDraftLikelihood: High

Description

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (510)

page 16 of 26
  • CVE-2021-29872MedJan 18, 2022
    risk 0.35cvss 5.4epss 0.01

    IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this…

  • CVE-2021-43410MedDec 9, 2021
    risk 0.35cvss 5.3epss 0.02

    Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1]…

  • CVE-2021-39367MedAug 23, 2021
    risk 0.35cvss 5.3epss 0.01

    Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.

  • CVE-2021-32796MedJul 27, 2021
    risk 0.35cvss 6.5epss 0.01

    xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected…

  • CVE-2021-20333MedJul 23, 2021
    risk 0.35cvss 5.3epss 0.01

    Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2…

  • CVE-2020-36173MedJan 6, 2021
    risk 0.35cvss 5.3epss 0.01

    The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.

  • CVE-2020-24592MedSep 25, 2020
    risk 0.35cvss 5.3epss 0.01

    Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.

  • CVE-2020-6261MedJul 1, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.

  • CVE-2020-10960MedApr 3, 2020
    risk 0.35cvss 5.3epss 0.01

    In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows…

  • CVE-2018-20586MedMar 12, 2020
    risk 0.35cvss 5.3epss 0.01

    bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.

  • CVE-2019-19714MedDec 17, 2019
    risk 0.35cvss 5.3epss 0.01

    Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.

  • CVE-2019-15944MedSep 5, 2019
    risk 0.35cvss 5.3epss 0.01

    In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.

  • CVE-2019-11717MedJul 23, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

  • CVE-2019-3571MedJul 16, 2019
    risk 0.35cvss 5.3epss 0.01

    An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.

  • CVE-2026-73411MedAug 12, 2026
    risk 0.34cvss epss 0.00

    Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when applications use the escape or escapeAll APIs on Unix with shell set to dash, or with shell set to true when…

  • CVE-2026-54705MedJul 29, 2026
    risk 0.34cvss 6.3epss 0.00

    MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup at src/core/box.ts, in xmlEscape, scanText, and text-mode output in src/formats/atom-to-math-ml.ts, and…

  • CVE-2026-2404MedApr 14, 2026
    risk 0.34cvss 5.3epss 0.00

    CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload.

  • CVE-2025-46583MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack.

  • CVE-2021-25254MedMay 21, 2025
    risk 0.34cvss 5.3epss 0.01

    Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.

  • CVE-2025-30657MedApr 9, 2025
    risk 0.34cvss 5.3epss 0.00

    An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for flow-monitoring receives a…