VYPR

CWE-644

Improper Neutralization of HTTP Headers for Scripting Syntax

VariantIncompleteLikelihood: High

Description

The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (64)

page 2 of 4
  • CVE-2025-14807MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site…

  • CVE-2025-27901MedFeb 17, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the…

  • CVE-2024-51451MedFeb 4, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session…

  • CVE-2024-39736MedJul 15, 2024
    risk 0.42cvss 6.5epss 0.00

    IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting,…

  • CVE-2026-72574MedAug 10, 2026
    risk 0.40cvss 6.1epss 0.00

    A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control the origin of JavaScript and CSS assets loaded by the default theme. When base_url is unset (the default), Pico::getBaseUrl in lib/Pico.php builds the base…

  • CVE-2026-1698MedFeb 26, 2026
    risk 0.40cvss 6.1epss 0.00

    A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints…

  • CVE-2025-63828MedNov 18, 2025
    risk 0.40cvss 6.1epss 0.00

    Host Header Injection vulnerability in Backdrop CMS 1.32.1 allows attackers to manipulate the Host header in password reset requests, leading to redirects to malicious domains and potential session hijacking via cookie injection.

  • CVE-2025-52647MedOct 10, 2025
    risk 0.40cvss 6.1epss 0.00

    The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks.

  • CVE-2025-40631MedMay 16, 2025
    risk 0.40cvss 6.1epss 0.00

    HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirected.

  • CVE-2025-27632MedMar 25, 2025
    risk 0.40cvss 6.1epss 0.00

    A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request to leverage multiple attack vectors, including defacing the site content through web-cache poisoning.

  • CVE-2025-23001MedJan 31, 2025
    risk 0.40cvss 6.1epss 0.00

    A Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host header. An attacker can manipulate the Host header in HTTP requests, which may lead to phishing attacks, reset password, or cache poisoning. NOTE:…

  • CVE-2021-20784MedJul 14, 2021
    risk 0.40cvss 6.1epss 0.01

    HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website that uses the product.

  • CVE-2026-55791MedJul 2, 2026
    risk 0.38cvss epss 0.00

    Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By…

  • CVE-2021-21265MedMar 10, 2021
    risk 0.37cvss 6.8epss 0.02

    October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October before version 1.1.2, when running on poorly configured servers (i.e. the server routes any request, regardless of the HOST header to an October CMS instance) the potential…

  • CVE-2026-54477MedJul 3, 2026
    risk 0.35cvss 5.4epss 0.00

    The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.

  • CVE-2025-66485MedApr 1, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or…

  • CVE-2025-13213MedMar 10, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning…

  • CVE-2025-36227MedMar 10, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers.  This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning…

  • CVE-2025-36223MedNov 12, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session…

  • CVE-2024-40686MedJul 23, 2025
    risk 0.35cvss 5.4epss 0.00

    IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable…