VYPR

CWE-791

Incomplete Filtering of Special Elements

BaseIncomplete

Description

The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (42)

page 2 of 3
  • CVE-2026-3725MedMar 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/mail/MailService.java of the component FreeMarker Template Handler. Executing a…

  • CVE-2025-14731MedDec 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special…

  • CVE-2025-6518MedJun 23, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py of the component Jinja2 Template Handler. The manipulation of the argument…

  • CVE-2025-5325MedMay 29, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /adpweb/a/ica/api/service/rfa/testServic…

  • CVE-2025-2040MedMar 6, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template…

  • CVE-2024-39283MedAug 14, 2024
    risk 0.39cvss 6.0epss 0.00

    Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-31172MedAug 31, 2023
    risk 0.38cvss 5.9epss 0.00

    An Incomplete Filtering of Special Elements vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual…

  • CVE-2026-19929MedAug 16, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulation leads to improper neutralization of…

  • CVE-2026-78140MedAug 23, 2026
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executing a manipulation can lead to improper…

  • CVE-2026-6984MedApr 25, 2026
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard API. The manipulation results in improper neutralization of special elements used in a…

  • CVE-2026-5987MedApr 9, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemarkerView.java of the component FreeMarker…

  • CVE-2026-3714MedMar 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in OpenCart 4.0.2.3. Affected by this issue is the function Save of the file admin/controller/design/template.php of the component Incomplete Fix CVE-2024-36694. Such manipulation leads to improper neutralization of special elements used in a…

  • CVE-2026-2969MedFeb 23, 2026
    risk 0.31cvss 4.7epss 0.01

    A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file datapizza-ai-core/datapizza/modules/prompt/prompt.py of the component Jinja2 Template Handler. This manipulation of the argument Prompt causes improper…

  • CVE-2025-2336MedJun 4, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS's 'ngSanitize' module allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing…

  • CVE-2025-0716MedApr 29, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing…

  • CVE-2024-8373MedSep 9, 2024
    risk 0.31cvss 4.8epss 0.01

    Improper sanitization of the value of the [srcset] attribute in HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This…

  • CVE-2025-9094MedAug 17, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has…

  • CVE-2024-39899MedJul 9, 2024
    risk 0.28cvss 5.3epss 0.01

    PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was to allow using the YOURLs URL shortener without running the YOURLs instance without authentication and/or exposing the…

  • CVE-2024-32162MedApr 17, 2024
    risk 0.28cvss 4.3epss 0.00

    CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.

  • CVE-2020-36827MedMar 24, 2024
    risk 0.28cvss 5.4epss 0.00

    The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.