VYPR

CWE-116

Improper Encoding or Escaping of Output

ClassDraftLikelihood: High

Description

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (510)

page 22 of 26
  • CVE-2022-34316LowNov 14, 2022
    risk 0.24cvss 3.7epss 0.01

    IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers. IBM X-Force ID: 229452.

  • CVE-2022-2099MedJul 17, 2022
    risk 0.24cvss 4.8epss 0.01

    The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitizing in the payment gateway titles

  • CVE-2026-33657MedApr 13, 2026
    risk 0.23cvss 4.6epss 0.00

    EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into system-generated email…

  • CVE-2025-12734LowDec 11, 2025
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious…

  • CVE-2025-30345LowMar 21, 2025
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most cases, HTML entities are encoded…

  • CVE-2023-3190MedJun 10, 2023
    risk 0.23cvss 4.6epss 0.01

    Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2015-10011MedJan 2, 2023
    risk 0.23cvss 4.6epss 0.01

    A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the file resolverapi/endpoints.py. The manipulation leads to improper output neutralization for logs. The identifier of the patch is…

  • CVE-2020-29023LowFeb 16, 2021
    risk 0.23cvss 3.5epss 0.01

    Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects:…

  • CVE-2026-35366MedApr 22, 2026
    risk 0.22cvss 4.4epss 0.00

    The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This…

  • CVE-2026-44458MedMay 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS…

  • CVE-2026-35651MedApr 10, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompts that allows attackers to spoof terminal output. Untrusted tool metadata can carry ANSI control sequences into approval prompts and permission logs, enabling…

  • CVE-2024-58266LowJul 27, 2025
    risk 0.21cvss 3.2epss 0.01

    The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

  • CVE-2023-26279LowNov 24, 2023
    risk 0.21cvss 3.3epss 0.00

    IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a local user to perform unauthorized actions due to improper encoding. IBM X-Force ID: 248160.

  • CVE-2022-0124MedJan 18, 2022
    risk 0.21cvss 4.3epss 0.01

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. Gitlab's Slack integration is incorrectly validating user input and allows to craft malicious URLs that are sent to slack.

  • CVE-2026-52846MedJun 23, 2026
    risk 0.20cvss 4.2epss 0.00

    Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic,…

  • CVE-2024-46901LowDec 9, 2024
    risk 0.20cvss 3.1epss 0.02

    Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. All versions of Subversion…

  • CVE-2024-4099LowSep 26, 2024
    risk 0.20cvss 3.1epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt…

  • CVE-2024-22229LowJan 24, 2024
    risk 0.20cvss 3.1epss 0.00

    Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs…

  • CVE-2023-37875LowSep 12, 2023
    risk 0.20cvss 3.0epss 0.00

    Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0.

  • CVE-2023-32301LowJun 13, 2023
    risk 0.20cvss 3.1epss 0.00

    Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, multiple duplicate topics could be created if topic embedding is enabled. This issue is patched in version 3.0.4 of…