CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Description
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9
CVEs mapped to this weakness (5,475)
page 227 of 274| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-6034 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2019 | a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors. | ||
| CVE-2019-15259 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of… | ||
| CVE-2019-16532 | Med | 0.40 | 6.1 | 0.01 | Sep 26, 2019 | An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections. | ||
| CVE-2019-5314 | Med | 0.40 | 6.1 | 0.01 | Sep 13, 2019 | Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability. | ||
| CVE-2014-10386 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. | ||
| CVE-2014-10394 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header. | ||
| CVE-2014-10391 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. | ||
| CVE-2019-1020006 | Med | 0.40 | 6.1 | 0.01 | Jul 29, 2019 | invenio-app before 1.1.1 allows host header injection. | ||
| CVE-2019-3562 | Med | 0.40 | 6.1 | 0.01 | Apr 29, 2019 | A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11. | ||
| CVE-2015-5462 | Med | 0.40 | 6.1 | 0.01 | Apr 3, 2019 | AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features. | ||
| CVE-2018-16627 | Med | 0.40 | 6.1 | 0.01 | Dec 20, 2018 | panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. | ||
| CVE-2018-1474 | Med | 0.40 | 6.1 | 0.01 | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to… | ||
| CVE-2018-18207 | Med | 0.40 | 6.1 | 0.01 | Oct 10, 2018 | Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter. | ||
| CVE-2018-1319 | Med | 0.40 | 6.1 | 0.02 | Mar 15, 2018 | In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session. | ||
| CVE-2018-6603 | Med | 0.40 | 6.1 | 0.01 | Feb 7, 2018 | Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie. | ||
| CVE-2026-41573 | — | Hig | 0.39 | — | 0.00 | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection added for CVE-2021-29156. The unescaped… | |
| CVE-2026-69097 | Hig | 0.39 | 7.0 | 0.00 | Aug 3, 2026 | GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's… | ||
| CVE-2026-58213 | Hig | 0.39 | 7.1 | 0.00 | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode… | ||
| CVE-2025-27511 | Hig | 0.39 | 7.2 | 0.01 | Jun 18, 2026 | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE).… | ||
| CVE-2022-21724 | Hig | 0.39 | 7.0 | 0.03 | Feb 2, 2022 | pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin… |
- risk 0.40cvss 6.1epss 0.01
a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of…
- risk 0.40cvss 6.1epss 0.01
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
- risk 0.40cvss 6.1epss 0.01
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.
- risk 0.40cvss 6.1epss 0.01
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
- risk 0.40cvss 6.1epss 0.01
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
- risk 0.40cvss 6.1epss 0.01
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
- risk 0.40cvss 6.1epss 0.01
invenio-app before 1.1.1 allows host header injection.
- risk 0.40cvss 6.1epss 0.01
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.
- risk 0.40cvss 6.1epss 0.01
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.
- risk 0.40cvss 6.1epss 0.01
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
- risk 0.40cvss 6.1epss 0.01
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to…
- risk 0.40cvss 6.1epss 0.01
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
- risk 0.40cvss 6.1epss 0.02
In Apache Allura prior to 1.8.1, attackers may craft URLs that cause HTTP response splitting. If a victim goes to a maliciously crafted URL, unwanted results may occur including XSS or service denial for the victim's browsing session.
- risk 0.40cvss 6.1epss 0.01
Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie.
- risk 0.39cvss —epss 0.00
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection added for CVE-2021-29156. The unescaped…
- risk 0.39cvss 7.0epss 0.00
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's…
- risk 0.39cvss 7.1epss 0.00
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as NATS protocol data to route or leafnode…
- risk 0.39cvss 7.2epss 0.01
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE).…
- risk 0.39cvss 7.0epss 0.03
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin…