Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-116 (对输出编码和转义不恰当) — Vulnerability Class 127

127 vulnerabilities classified as CWE-116 (对输出编码和转义不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-32074 XSSes in Extension:ConfirmAccount — Mediawiki - Confirm Account Extension 6.1AIMediumAI2025-04-11
CVE-2025-30657 Junos OS: Processing of a specific BGP update causes the SRRD process to crash — Junos OS 5.3 Medium2025-04-09
CVE-2025-30345 OpenSlides 安全漏洞 — OpenSlides 3.5 Low2025-03-21
CVE-2024-50629 Synology DiskStation Manager(DSM)和Synology BeeStation Manager 安全漏洞 — DiskStation Manager (DSM) 5.3 Medium2025-03-19
CVE-2024-10441 Synology DiskStation Manager(DSM)和Synology BeeStation Manager 安全漏洞 — DiskStation Manager (DSM) 9.8 Critical2025-03-19
CVE-2025-27109 Lack of Escaping of HTML in JSX Fragments allows for Cross-site Scripting in solid-js — solid 7.3 High2025-02-21
CVE-2025-24025 Coolify Vulnerable to Reflected XSS on Tag Search — coolify 5.4 -2025-01-24
CVE-2024-56277 WordPress Poll Maker Plugin < 5.5.5 - HTML Injection vulnerability — Poll Maker 8.2 -2025-01-21
CVE-2025-23207 \htmlData does not validate attribute names in KaTeX — KaTeX 6.3 Medium2025-01-17
CVE-2024-52005 The sideband payload is passed unfiltered to the terminal in git — git 8.2 -2025-01-15
CVE-2024-50349 Git does not sanitize URLs when asking for credentials interactively — git 8.8 -2025-01-14
CVE-2024-52006 Newline confusion in credential helpers can lead to credential exfiltration in git — git 8.8 -2025-01-14
CVE-2024-9427 Koji: escape html tag characters in the query string 5.4 Medium2024-12-24
CVE-2024-55663 XWiki Platform has an SQL injection in getdocuments.vm with sort parameter — xwiki-platform 8.8 -2024-12-12
CVE-2024-47845 CSS sanitizer used incorrectly, and is easily bypassed — Mediawiki - CSS Extension 9.4 -2024-10-05
CVE-2024-47528 LibreNMS Contains a Stored XSS via File Upload — librenms 4.8 -2024-10-01
CVE-2024-47531 Scout contains insufficient output escaping of attachment names — scout 4.6 Medium2024-09-30
CVE-2024-4099 Improper Encoding or Escaping of Output in GitLab — GitLab 3.1 Low2024-09-26
CVE-2024-45498 Apache Airflow: Command Injection in an example DAG — Apache Airflow 8.8 -2024-09-07
CVE-2024-45299 alf.io's preloaded data as json is not escaped correctly — alf.io 6.5 Medium2024-09-06
CVE-2024-38177 Windows App Installer Spoofing Vulnerability — App Installer 7.8 High2024-08-13
CVE-2024-6329 Improper Encoding or Escaping of Output in GitLab — GitLab 5.7 Medium2024-08-08
CVE-2024-39682 WordPress Cooked Plugin - Authenticated (Contributor+) HTML Injection via Recipe Excerpt — Cooked 6.4 Medium2024-07-17
CVE-2024-38475 Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path. — Apache HTTP Server 9.8AICriticalAI2024-07-01
CVE-2024-38474 Apache HTTP Server weakness with encoded question marks in backreferences — Apache HTTP Server 9.8AICriticalAI2024-07-01
CVE-2024-38473 Apache HTTP Server proxy encoding problem — Apache HTTP Server 9.8AICriticalAI2024-07-01
CVE-2024-5585 Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix) — PHP 7.7 High2024-06-09
CVE-2024-4177 Host whitelist parser issue in GravityZone Console On-Premise (VA-11554) — GravityZone Console On-Premise 8.1 High2024-06-06
CVE-2024-4420 Denial of Service in Tink-cc — Tink 7.5AIHighAI2024-05-21
CVE-2024-34355 TYPO3 vulnerable to an HTML Injection in the History Module — typo3 3.5 Low2024-05-14

Vulnerabilities classified as CWE-116 (对输出编码和转义不恰当) represent 127 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.