CWE-74
5,292 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,292)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Gravitatedesign 1Gravitate Qa Tracker Nov 21, 2024 Sep 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. |
1Sitebuilder Dynamic Components Project 1Sitebuilder Dynamic Components Nov 21, 2024 Sep 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request. |
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of...Show more |
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several...Show more |
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability is due to improper restrictions on softw...Show more |
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. |
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header. |
1Wpsupportplus 1Wp Support Plus Responsive Ticket System Nov 21, 2024 Aug 22, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. |
1Post Pay Counter Project 1Post Pay Counter Nov 21, 2024 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection. |
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulne...Show more |
1Hp 13par Storeserv Management Console Jun 17, 2026 Aug 9, 2019 N/A· v4 8.8 HIGH· v3 8.7 HIGH· v2 A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. |
cPanel before 58.0.4 has improper session handling for shared users (SEC-139). |
An injection vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. An authenticated use...Show more |
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240). |
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318). |
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314). |
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313). |
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80). |
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78). |
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). |