VYPR

CWE-75

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)

ClassDraft

Description

The product does not adequately filter user-controlled input for special elements with control implications.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-81 · CAPEC-93

CVEs mapped to this weakness (41)

page 1 of 3
  • CVE-2021-22911CriMay 27, 2021
    risk 0.74cvss 9.8epss 0.95

    A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.

  • CVE-2024-39227CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain insecure permissions in the endpoint…

  • CVE-2024-39243CriJun 26, 2024
    risk 0.64cvss 9.8epss 0.00

    An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

  • CVE-2024-35373CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

  • CVE-2021-22910CriAug 9, 2021
    risk 0.64cvss 9.8epss 0.02

    A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.

  • CVE-2024-27708CriDec 22, 2025
    risk 0.62cvss 9.6epss 0.01

    Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.

  • CVE-2022-24039CriMay 10, 2022
    risk 0.59cvss 9.0epss 0.02

    A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The “addCell” JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of…

  • CVE-2021-39174HigAug 28, 2021
    risk 0.58cvss 8.8epss 0.04

    Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret (`APP_KEY`) and various passwords (email,…

  • CVE-2021-32798CriAug 9, 2021
    risk 0.58cvss 10.0epss 0.02

    The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an…

  • CVE-2026-29042CriMar 6, 2026
    risk 0.57cvss 9.8epss 0.02

    Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a command injection vulnerability in how it processes user-supplied arguments. When a function is invoked via HTTP, the runtime…

  • CVE-2025-50213CriJun 24, 2025
    risk 0.57cvss 9.8epss 0.01

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added…

  • CVE-2024-37779HigSep 23, 2024
    risk 0.57cvss 8.8epss 0.01

    WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

  • CVE-2024-31809HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.

  • CVE-2023-40743CriSep 5, 2023
    risk 0.57cvss 9.8epss 0.03

    ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API…

  • CVE-2023-27533HigMar 30, 2023
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send…

  • CVE-2023-23912HigFeb 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface…

  • CVE-2022-48217HigJan 4, 2023
    risk 0.53cvss 8.1epss 0.01

    The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled…

  • CVE-2026-31908CriApr 14, 2026
    risk 0.52cvss 9.1epss 0.01

    Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which…

  • CVE-2024-0801HigMar 13, 2024
    risk 0.52cvss 7.5epss 0.42

    A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

  • CVE-2024-23274HigMar 8, 2024
    risk 0.51cvss 7.8epss 0.00

    An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to elevate privileges.