CWE-116
522 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
CVEs (522)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhpmailer+1 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay process...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SAP Business Objects Business Intelligence Platform (CMS / Auditing issues), version 4.2, allows attacker to send specially crafted GIOP packets to several services due to Improper Input Validation, allowing to forge add...Show more |
1Ibm 1Security Information Queue Jun 17, 2026 Apr 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow an authenticated user to perform unauthorized actions by bypassing illegal character restrictions. X-Force ID: 176205. |
bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call. |
An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, be...Show more |
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009. |
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered. |
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is r...Show more |
1Cisco 10Firepower 4110 Firmware Firepower 4115 FirmwareFirepower 4120 Firmware+7 moreAug 11, 2026 Oct 2, 2019 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands wit...Show more |
1Cisco 10Firepower 4110 Firmware Firepower 4115 FirmwareFirepower 4120 Firmware+7 moreAug 11, 2026 Oct 2, 2019 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands wit...Show more |
LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls t...Show more |
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manage...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request no...Show more |
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of...Show more |
1Valvesoftware 1Counter Strike Jun 17, 2026 Sep 5, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message. |
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to incorrect validation of...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Aug 15, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the sha...Show more |
1Jenkins 1Configuration As Code Jun 17, 2026 Jul 31, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system conf...Show more |
4Debian MozillaNovell+1 more5Debian Linux FirefoxLeap+2 moreJun 17, 2026 Jul 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Fir...Show more |
An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send files to users that would be displayed with a wrong extension. |