← Back
CWE-74

4,976 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

JSON object

Loading...

CVEs (4,976)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tagdiv
1Newspaper
Nov 21, 2024
Sep 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
1Arubanetworks
1Arubaos
Jun 17, 2026
Sep 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger...Show more
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.Show less
1Cybozu
1Garoon
Jun 17, 2026
Sep 12, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.
1Apache
1Ofbiz
Jun 17, 2026
Sep 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manage...Show more
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good reason and never within a field that accepts user input. Mitigation: Upgrade to 16.11.06 or manually apply the following commit on branch 16.11: r1858533Show less
1Gravitatedesign
1Gravitate Qa Tracker
Nov 21, 2024
Sep 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
1Sitebuilder Dynamic Components Project
1Sitebuilder Dynamic Components
Nov 21, 2024
Sep 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
1Librenms
1Librenms
Jun 17, 2026
Sep 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of...Show more
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the html/graph.php and html/graph-realtime.php scripts. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, disclosing file content, denial of service, or writing arbitrary files. NOTE: relative to CVE-2019-10665, this requires authentication and the pathnames differ.Show less
1Librenms
1Librenms
Jun 17, 2026
Sep 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several...Show more
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the html/graph.php script. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, file content, denial of service, or writing arbitrary files.Show less
1Cisco
1Webex Teams
Jun 17, 2026
Sep 5, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on softw...Show more
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on software logging features used by the application on Windows operating systems. An attacker could exploit this vulnerability by convincing a targeted user to visit a website designed to submit malicious input to the affected application. A successful exploit could allow the attacker to cause the application to modify files and execute arbitrary commands on the system with the privileges of the targeted user.Show less
13cx
1Live Chat
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
1Saschart
1Rich Counter
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
1Post Pay Counter Project
1Post Pay Counter
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
1Atlassian
1Jira Server
Jun 17, 2026
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulne...Show more
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.Show less
1Hp
13par Storeserv Management Console
Jun 17, 2026
Aug 9, 2019
N/A· v4
8.8 HIGH· v3
8.7 HIGH· v2
A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated use...Show more
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated user with marketing manipulation privileges can invoke methods that alter data of the underlying model followed by corresponding database modifications.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).