CWE-707: Improper Neutralization
The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.
249 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-10915 — D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
- CVE-2024-10914 — D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
- CVE-2026-18613 — GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
- CVE-2026-5002 — PromtEngineer localGPT LLM Prompt server.py _route_using_overviews injection
- CVE-2025-11445 — Kilo Code Prompt ClineProvider.ts ClineProvider injection
- CVE-2024-10845 — 1000 Projects Bookstore Management System book_detail.php sql injection
- CVE-2024-10844 — 1000 Projects Bookstore Management System search.php sql injection
- CVE-2024-10791 — Codezips Hospital Appointment System doctorAction.php sql injection
- CVE-2024-10752 — Codezips Pet Shop Management System productsadd.php sql injection
- CVE-2026-20278 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-4249 — Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
- CVE-2026-6994 — Envoy Query Parameter header_mutation.cc params.add injection
- CVE-2025-24921 — Improper neutralization for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform
- CVE-2025-0697 — Telstra Smart Modem Gen 2 HTTP Header injection
- CVE-2026-4516 — Foundation Agents MetaGPT DataInterpreter write_analysis_code.py injection
- CVE-2026-4511 — vanna-ai vanna legacy exec injection
- CVE-2026-4500 — bagofwords1 bagofwords code_execution.py generate_df injection
- CVE-2026-3992 — CodeGenieApp serverless-express Users Endpoint dynamodb.ts injection
- CVE-2026-3813 — opencc JFlow WF_CCForm.java Calculate injection
- CVE-2025-13268 — Dromara dataCompare JDBC URL DbconfigServiceImpl.java DbConfig injection
Recently published
- CVE-2026-20278 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-76993 — GreyDGL PentestGPT Web-Page Crawling injection
- CVE-2026-18613 — GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
- CVE-2026-4249 — Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption
- CVE-2026-11457 — erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection
- CVE-2026-10661 — ahujasid blender-mcp server.py open injection
- CVE-2026-10223 — NousResearch hermes-agent memory_tool.py _scan_memory_content injection
- CVE-2026-10222 — NousResearch hermes-agent config.py _sanitize_env_lines injection
- CVE-2026-10221 — NousResearch hermes-agent run_agent.py _compress_context injection
- CVE-2026-10220 — NousResearch hermes-agent skills_tool.py skill_view injection
- CVE-2026-10210 — AstrBotDevs AstrBot skill_manager.py _sanitize_prompt_description injection
- CVE-2026-9422 — KLiK SocialMediaWebsite HTTP POST Request Parameter injection
- CVE-2026-9420 — KLiK SocialMediaWebsite HTTP GET Request Parameter injection
- CVE-2026-9366 — NousResearch hermes-agent prompt_builder.py _scan_context_content injection
- CVE-2026-9353 — NousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py injection
- CVE-2026-7045 — baomidou dynamic-datasource StandardEvaluationContext/SpelExpressionParser DsSpelExpressionProcessor.java DsSpelExpressionProcessor#doDetermineDatasource injection
- CVE-2026-6994 — Envoy Query Parameter header_mutation.cc params.add injection
- CVE-2026-6599 — langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection
- CVE-2026-5561 — Campcodes Complete POS Management and Inventory System Environment Variable SettingsController.php injection
- CVE-2026-5002 — PromtEngineer localGPT LLM Prompt server.py _route_using_overviews injection
More specific weaknesses
- CWE-116 — Improper Encoding or Escaping of Output
- CWE-138 — Improper Neutralization of Special Elements
- CWE-1426 — Improper Validation of Generative AI Output
- CWE-170 — Improper Null Termination
- CWE-172 — Encoding Error
- CWE-182 — Collapse of Data into Unsafe Value
- CWE-20 — Improper Input Validation
- CWE-228 — Improper Handling of Syntactically Invalid Structure
- CWE-463 — Deletion of Data Structure Sentinel
- CWE-74 — Injection