CWE-74
4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (4,976)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. |
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger...Show more |
Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'. |
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manage...Show more |
1Gravitatedesign 1Gravitate Qa Tracker Nov 21, 2024 Sep 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. |
1Sitebuilder Dynamic Components Project 1Sitebuilder Dynamic Components Nov 21, 2024 Sep 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. |
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of...Show more |
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several...Show more |
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on softw...Show more |
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. |
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header. |
1Wpsupportplus 1Wp Support Plus Responsive Ticket System Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. |
1Post Pay Counter Project 1Post Pay Counter Nov 21, 2024 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection. |
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulne...Show more |
1Hp 13par Storeserv Management Console Jun 17, 2026 Aug 9, 2019 N/A· v4 8.8 HIGH· v3 8.7 HIGH· v2 A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. |
cPanel before 58.0.4 has improper session handling for shared users (SEC-139). |
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated use...Show more |
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240). |
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318). |
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314). |