Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-116 (对输出编码和转义不恰当) — Vulnerability Class 127

127 vulnerabilities classified as CWE-116 (对输出编码和转义不恰当). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-29894 Cacti Cross-site Scripting vulnerability when using JavaScript based messaging API — cacti 5.4 Medium2024-05-13
CVE-2024-1874 Command injection via array-ish $command parameter of proc_open() — PHP 9.4 Critical2024-04-29
CVE-2024-31866 Apache Zeppelin: Interpreter download command does not escape malicious code injection — Apache Zeppelin 9.8AICriticalAI2024-04-09
CVE-2024-28245 KaTeX's \includegraphics does not escape filename — KaTeX 6.3 Medium2024-03-25
CVE-2024-27938 SMTP Smuggling in Postal — postal 5.3 Medium2024-03-11
CVE-2023-26279 IBM QRadar WinCollect Agent improper output encoding — QRadar WinCollect Agent 3.3 Low2023-11-23
CVE-2023-4393 HTML and SMTP Injection in LiquidFiles — LiquidFiles 5.4 Medium2023-10-29
CVE-2023-45135 XWiki users can be tricked to execute scripts as the create page action doesn't display the page's title — xwiki-platform 9.1 Critical2023-10-25
CVE-2023-37875 Cross-Site Scripting Vulnerability in Wing FTP Server <= 7.2.0 — Wing FTP Server 3.0 Low2023-09-12
CVE-2023-40014 OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSender — openzeppelin-contracts 5.3 Medium2023-08-10
CVE-2023-35941 Envoy vulnerable to OAuth2 credentials exploit with permanent validity — envoy 8.6 High2023-07-25
CVE-2023-3668 Improper Encoding or Escaping of Output in froxlor/froxlor — froxlor/froxlor 8.3 -2023-07-14
CVE-2023-24480 Controller stack overflow when decoding messages from the server — C300 9.8 Critical2023-07-13
CVE-2023-2200 Improper Encoding or Escaping of Output in GitLab — GitLab 4.1 Medium2023-07-13
CVE-2023-3552 Improper Encoding or Escaping of Output in nilsteampassnet/teampass — nilsteampassnet/teampass 8.3 -2023-07-08
CVE-2023-32301 Discourse's canonical url not being used for topic embeddings — discourse 3.1 Low2023-06-13
CVE-2023-3190 Improper Encoding or Escaping of Output in nilsteampassnet/teampass — nilsteampassnet/teampass 8.3 -2023-06-10
CVE-2023-32071 XWiki Platform vulnerable to RXSS via editor parameter - importinline template — xwiki-platform 9.1 Critical2023-05-09
CVE-2023-28101 Flatpak metadata with ANSI control codes can cause misleading terminal output — flatpak 5.0 Medium2023-03-16
CVE-2023-26472 XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile — xwiki-platform 10.0 Critical2023-03-02
CVE-2022-45143 Apache Tomcat: JsonErrorReportValve escaping — Apache Tomcat 7.5 -2023-01-03
CVE-2022-23079 motoradmin - host header Injection in the reset password functionality — motor-admin 8.8 -2022-06-22
CVE-2022-29599 Commandline class shell injection vulnerabilities — Apache Maven 9.8 -2022-05-23
CVE-2021-41191 API giving out files without key — Roblox-Purchasing-Hub 7.5 High2021-10-27
CVE-2021-41132 Inconsistent input sanitisation leads to XSS vectors — omero-web 9.8 Critical2021-10-14
CVE-2021-39170 Improper Encoding or Escaping of Output in Asset Metadata Component — pimcore 8.0 High2021-09-01
CVE-2021-34630 Reflected XSS in GTranslate Pro and GTranslate Enterprise < 2.8.65 — GTranslate Pro and GTranslate Enterprise 5.0 Medium2021-07-30
CVE-2021-32796 Misinterpretation of malicious XML input in xmldom — xmldom 6.5 Medium2021-07-27
CVE-2021-32679 Filenames not escaped by default in controllers using DownloadResponse — security-advisories 3.5 Low2021-07-12
CVE-2021-23205 Gallagher Command Centre Server 处理逻辑错误漏洞 — Command Centre 8.1 High2021-06-11

Vulnerabilities classified as CWE-116 (对输出编码和转义不恰当) represent 127 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.