CWE-116: Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
290 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-20245 — Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
- CVE-2025-55730 — XWiki Remote Macros vulnerable to remote code execution using the confluence paste code macro
- CVE-2025-55729 — XWiki Remote Macros vulnerable to remote code execution using the ConfluenceLayoutSection macro
- CVE-2025-49013 — WilderForge vulnerable to code Injection via GitHub Actions Workflows
- CVE-2024-10441 — Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before
- CVE-2026-22792 — 5ire vulnerable to Remote Code Execution (RCE)
- CVE-2024-38475 — Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
- CVE-2025-59936 — get-jwks poisoned JWKS cache allows post-fetch issuer validation bypass
- CVE-2025-59158 — Coolify has Stored XSS in Project Name
- CVE-2024-1874 — Command injection via array-ish $command parameter of proc_open()
- CVE-2026-32754 — FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})
- CVE-2024-22199 — Django Template Engine Vulnerable to XSS
- CVE-2025-40547 — SolarWinds Serv-U Logic Abuse - Remote Code Execution Vulnerability
- CVE-2025-32974 — org.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't consider TextAreas with default content type
- CVE-2026-27169 — OpenSift: Persistent XSS Chat Tool Rendering
- CVE-2026-34483 — Apache Tomcat: Incomplete escaping of JSON access logs
- CVE-2025-11085 — FactoryTalk® DataMosaix™ Private Cloud – Persistent XSS
- CVE-2025-9127 — PX Enterprise Improper Sanitization Vulnerability
- CVE-2025-64325 — Emby Server is Vulnerable to Remote Code Execution Through XSS in Admin Dashboard
- CVE-2025-1308 — PX Backup Improper Sanitization Vulnerability
Recently published
- CVE-2026-88921 — MISP: Unescaped HTML Injection in PDF Report Element Rendering
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-79964 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79952 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-87550 — Improper encoding or escaping of output in CSS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to pote
- CVE-2026-82756 — ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authenticate challenge without escaping, allowing header parameter injection
- CVE-2026-52772 — YesWiki: Bazar form-field templates still apply `|raw('html')` to `field.label` / `field.hint` in attribute and label-body contexts — stored XSS in form renders (sibling class of commit `e6b66aa`)
- CVE-2026-84292 — fast-uri vulnerable to authority injection via an unvalidated port in serialize
- CVE-2026-82958 — In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a Cr
- CVE-2026-83610 — xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization
- CVE-2026-77353 — Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export
- CVE-2026-82681 — Query-parameter injection in AshAdmin row-action links via unencoded string primary keys
- CVE-2026-55859 — MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output in org.mariadb:r2dbc-mariadb
- CVE-2026-55855 — MariaDB Connector/Node.js: Possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
- CVE-2026-55891 — PrivateBin: Reflected JSON injection in backend responses via unescaped REQUEST_URI
- CVE-2026-82249 — gitoxide before 0.38.2 Credential Helper Protocol Field Injection
- CVE-2026-81522 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ Driver
- CVE-2026-81685 — openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata
- CVE-2026-65085 — NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper en
- CVE-2026-55618 — eml_parser: URL extraction bypass via HTML entities in URLs