VYPR

CWE-116

Improper Encoding or Escaping of Output

ClassDraftLikelihood: High

Description

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-104 · CAPEC-73 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (561)

page 27 of 29
  • CVE-2026-62184HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote…

  • CVE-2026-58487MedJul 13, 2026
    risk 0.00cvss —epss 0.00

    HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe handling of the local-part of registered email addresses, HedgeDoc was vulnerable to stored HTML Injection through its publish and slide views. An attacker…

  • CVE-2026-55659HigJul 10, 2026
    risk 0.00cvss 7.7epss 0.00

    Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-site scripting. On the main application…

  • CVE-2026-59833HigJul 9, 2026
    risk 0.00cvss —epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes,…

  • CVE-2026-54893LowJul 6, 2026
    risk 0.00cvss —epss 0.00

    URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API request URL by interpolating the sender's email address into the URL path (/users/{from}/sendMail) without percent-encoding or validation. In applications that…

  • CVE-2026-49091HigJul 1, 2026
    risk 0.00cvss 8.0epss 0.00

    Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently…

  • CVE-2026-47206LowJun 26, 2026
    risk 0.00cvss —epss 0.00

    Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer. An authenticated user can inject arbitrary RESP messages into the connection's response stream,…

  • CVE-2026-21443MedFeb 25, 2026
    risk 0.00cvss 6.1epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translation function returns unescaped strings. While wrapper functions exist for escaping in different contexts (`xlt()` for HTML, `xla()`…

  • CVE-2026-26953MedFeb 19, 2026
    risk 0.00cvss 5.4epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions table located on the API settings page, allowing an attacker…

  • CVE-2026-26952MedFeb 19, 2026
    risk 0.00cvss 5.4epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through the local DNS records configuration page, which allows an authenticated…

  • CVE-2026-24127MedJan 23, 2026
    risk 0.00cvss 5.4epss 0.00

    Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper…

  • CVE-2026-23630MedJan 21, 2026
    risk 0.00cvss 5.4epss 0.00

    Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code block rendering is vulnerable to stored Cross-Site Scripting (XSS). The frontend can render attacker-controlled Mermaid diagrams using mermaid.render(), then…

  • CVE-2025-68460HigDec 18, 2025
    risk 0.00cvss 7.2epss 0.00

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

  • CVE-2025-66548LowDec 5, 2025
    risk 0.00cvss 3.3epss 0.00

    Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, file extension can be spoofed by using RTLO characters, tricking users into download files with a…

  • CVE-2025-46340HigMay 5, 2025
    risk 0.00cvss 7.2epss 0.00

    Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPreviewService` and `MkUrlPreview`, it is possible for an attacker to inject arbitrary CSS into the…

  • CVE-2024-52006HigJan 14, 2025
    risk 0.00cvss 7.5epss 0.01

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information between Git and Git credential helpers.…

  • CVE-2024-50349MedJan 14, 2025
    risk 0.00cvss 4.7epss 0.01

    Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using any credential helper), it prints out…

  • CVE-2024-47531MedSep 30, 2024
    risk 0.00cvss 4.6epss 0.00

    Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly…

  • CVE-2024-45299MedSep 6, 2024
    risk 0.00cvss 6.5epss 0.01

    alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctly, the administrator / event admin could break their own install by inserting non correctly escaped…

  • CVE-2024-8297MedAug 29, 2024
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. Affected is the function JwtRefreshAuth of the file middleware/jwt_refresh_token_middleware.go. The manipulation of the argument Authorization leads to improper…