CWE-86: Improper Neutralization of Invalid Characters in Identifiers in Web Pages
The product does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.
10 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-20168 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
- CVE-2025-20167 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
- CVE-2025-20166 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
- CVE-2026-71478 — league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
- CVE-2026-28417 — Vim has OS Command Injection in netrw
- CVE-2025-66606 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl
Recently published
- CVE-2026-71478 — league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
- CVE-2026-28417 — Vim has OS Command Injection in netrw
- CVE-2025-66606 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl
- CVE-2025-20168 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
- CVE-2025-20167 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability
- CVE-2025-20166 — Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability