Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-116 (对输出编码和转义不恰当) — Vulnerability Class 127

127 vulnerabilities classified as CWE-116 (对输出编码和转义不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-42040 Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams — axios 3.7 Low2026-04-24
CVE-2026-40567 FreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature Variables — freescout 5.8 Medium2026-04-21
CVE-2026-6058 Zyxel WRE6505 安全漏洞 — WRE6505 v2 firmware 4.5 Medium2026-04-21
CVE-2026-20136 Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability — Cisco Identity Services Engine Software 6.0 Medium2026-04-15
CVE-2026-2404 Schneider Electric PowerChute Serial Shutdown 安全漏洞 — PowerChute™ Serial Shutdown 7.5 -2026-04-14
CVE-2026-40023 Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters — Apache Log4cxx 5.3 -2026-04-10
CVE-2026-40021 Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters — Apache Log4net 9.1 -2026-04-10
CVE-2026-34481 Apache Log4j JSON Template Layout: Improper serialization of non-finite floating-point values in JsonTemplateLayout — Apache Log4j JSON Template Layout 4.8 -2026-04-10
CVE-2026-34480 Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters — Apache Log4j Core 5.8AIMediumAI2026-04-10
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters — Apache Log4j 1 to Log4j 2 bridge 6.5AIMediumAI2026-04-10
CVE-2026-34483 Apache Tomcat: Incomplete escaping of JSON access logs — Apache Tomcat 9.8AICriticalAI2026-04-09
CVE-2026-25932 GLPI has Stored XSS in Supplier 'Website' field — glpi 7.2 High2026-04-06
CVE-2026-32811 Heimdall: Path received via Envoy gRPC corrupted when containing query string — heimdall 8.2 High2026-03-20
CVE-2026-33301 OpenEMR has arbitrary image file read via PDF generator — openemr 3.5 -2026-03-19
CVE-2026-31898 jsPDF has a PDF Object Injection via FreeText color — jsPDF 8.1 High2026-03-18
CVE-2025-12697 Improper Encoding or Escaping of Output in GitLab — GitLab 2.2 Low2026-03-11
CVE-2026-28350 lxml_html_clean: <base> tag injection through default Cleaner configuration — lxml_html_clean 6.1 Medium2026-03-05
CVE-2026-28348 lxml_html_clean: CSS @import Filter Bypass via Unicode Escapes — lxml_html_clean 6.1 Medium2026-03-05
CVE-2026-27812 Sub2API Vulnerable to Password Reset Poisoning via Host Header Trust Issue, Leading to Account Takeover — sub2api 8.8AIHighAI2026-02-26
CVE-2026-21443 OpenEMR allows inconsistent escaping of translation function output — openemr 6.1 -2026-02-25
CVE-2026-25940 jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property) — jsPDF 8.1 High2026-02-19
CVE-2025-15312 Tanium addressed an improper output sanitization vulnerability in TanOS. — Tanium Appliance 6.6 Medium2026-02-05
CVE-2026-25543 HtmlSanitizer has a bypass via template tag — HtmlSanitizer 6.1AIMediumAI2026-02-04
CVE-2026-24737 jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution — jsPDF 8.1 High2026-02-02
CVE-2025-66488 Discourse allows script execution in uploaded HTML/XML files on S3 — discourse 4.6 Medium2026-01-28
CVE-2026-24439 Tenda W30E V2 Lacks X-Content-Type-Options Header — W30E V2 9.4AICriticalAI2026-01-26
CVE-2026-22792 5ire vulnerable to Remote Code Execution (RCE) — 5ire 9.7 Critical2026-01-21
CVE-2026-22712 ApprovedRevs allows bypassing the inline CSS sanitizer — Mediawiki - ApprovedRevs Extension 9.1 -2026-01-09
CVE-2025-59158 Coolify has Stored XSS in Project Name — coolify 5.4 -2026-01-05
CVE-2025-68460 Roundcube Webmail 安全漏洞 — Webmail 7.2 High2025-12-18

Vulnerabilities classified as CWE-116 (对输出编码和转义不恰当) represent 127 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.