CWE-116
Improper Encoding or Escaping of Output
Description
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85
CVEs mapped to this weakness (510)
page 16 of 26| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-29872 | Med | 0.35 | 5.4 | 0.01 | Jan 18, 2022 | IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this… | ||
| CVE-2021-43410 | Med | 0.35 | 5.3 | 0.02 | Dec 9, 2021 | Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1]… | ||
| CVE-2021-39367 | Med | 0.35 | 5.3 | 0.01 | Aug 23, 2021 | Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection. | ||
| CVE-2021-32796 | Med | 0.35 | 6.5 | 0.01 | Jul 27, 2021 | xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected… | ||
| CVE-2021-20333 | Med | 0.35 | 5.3 | 0.01 | Jul 23, 2021 | Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2… | ||
| CVE-2020-36173 | Med | 0.35 | 5.3 | 0.01 | Jan 6, 2021 | The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields. | ||
| CVE-2020-24592 | Med | 0.35 | 5.3 | 0.01 | Sep 25, 2020 | Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization. | ||
| CVE-2020-6261 | Med | 0.35 | 5.3 | 0.01 | Jul 1, 2020 | SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired. | ||
| CVE-2020-10960 | Med | 0.35 | 5.3 | 0.01 | Apr 3, 2020 | In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows… | ||
| CVE-2018-20586 | Med | 0.35 | 5.3 | 0.01 | Mar 12, 2020 | bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call. | ||
| CVE-2019-19714 | Med | 0.35 | 5.3 | 0.01 | Dec 17, 2019 | Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered. | ||
| CVE-2019-15944 | Med | 0.35 | 5.3 | 0.01 | Sep 5, 2019 | In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message. | ||
| CVE-2019-11717 | Med | 0.35 | 5.3 | 0.02 | Jul 23, 2019 | A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | ||
| CVE-2019-3571 | Med | 0.35 | 5.3 | 0.01 | Jul 16, 2019 | An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension. | ||
| CVE-2026-73411 | Med | 0.34 | — | 0.00 | Aug 12, 2026 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when applications use the escape or escapeAll APIs on Unix with shell set to dash, or with shell set to true when… | ||
| CVE-2026-54705 | Med | 0.34 | 6.3 | 0.00 | Jul 29, 2026 | MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup at src/core/box.ts, in xmlEscape, scanText, and text-mode output in src/formats/atom-to-math-ml.ts, and… | ||
| CVE-2026-2404 | Med | 0.34 | 5.3 | 0.00 | Apr 14, 2026 | CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload. | ||
| CVE-2025-46583 | Med | 0.34 | 5.3 | 0.00 | Oct 27, 2025 | There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack. | ||
| CVE-2021-25254 | Med | 0.34 | 5.3 | 0.01 | May 21, 2025 | Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar. | ||
| CVE-2025-30657 | Med | 0.34 | 5.3 | 0.00 | Apr 9, 2025 | An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for flow-monitoring receives a… |
- risk 0.35cvss 5.4epss 0.01
IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this…
- risk 0.35cvss 5.3epss 0.02
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some HTTP request parameters are logged without first being escaped. Versions affected: master branch before commit 3c5d8c7 [1] of airavata-django-portal [1]…
- risk 0.35cvss 5.3epss 0.01
Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.
- risk 0.35cvss 6.5epss 0.01
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected…
- risk 0.35cvss 5.3epss 0.01
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2…
- risk 0.35cvss 5.3epss 0.01
The Ninja Forms plugin before 3.4.28 for WordPress lacks escaping for submissions-table fields.
- risk 0.35cvss 5.3epss 0.01
Mitel MiCloud Management Portal before 6.1 SP5 could allow an attacker, by sending a crafted request, to view system information due to insufficient output sanitization.
- risk 0.35cvss 5.3epss 0.01
SAP Solution Manager (Trace Analysis), version 7.20, allows an attacker to perform a log injection into the trace file, due to Incomplete XML Validation. The readability of the trace file is impaired.
- risk 0.35cvss 5.3epss 0.01
In MediaWiki before 1.34.1, users can add various Cascading Style Sheets (CSS) classes (which can affect what content is shown or hidden in the user interface) to arbitrary DOM nodes via HTML content within a MediaWiki page. This occurs because jquery.makeCollapsible allows…
- risk 0.35cvss 5.3epss 0.01
bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.
- risk 0.35cvss 5.3epss 0.01
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
- risk 0.35cvss 5.3epss 0.01
In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.
- risk 0.35cvss 5.3epss 0.02
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
- risk 0.35cvss 5.3epss 0.01
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension.
- risk 0.34cvss —epss 0.00
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when applications use the escape or escapeAll APIs on Unix with shell set to dash, or with shell set to true when…
- risk 0.34cvss 6.3epss 0.00
MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup at src/core/box.ts, in xmlEscape, scanText, and text-mode output in src/formats/atom-to-math-ml.ts, and…
- risk 0.34cvss 5.3epss 0.00
CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload.
- risk 0.34cvss 5.3epss 0.00
There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack.
- risk 0.34cvss 5.3epss 0.01
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
- risk 0.34cvss 5.3epss 0.00
An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). When a device configured for flow-monitoring receives a…