CWE-116: CWE-116

80
Total CVEs
25
Critical
25
High
7.5
Avg CVSS

Yearly Trend

2026
12
2025
32
2024
14
2023
9
2022
7

Top Affected Vendors

1 Mozilla 5
2 Apache 5
3 Debian 4
4 Gitlab 3
5 Hallowelt 3
6 Git 3
7 Netapp 2
8 Fedoraproject 2
9 Ibm 2
10 Coollabs 2

All CWE-116 CVEs (80)

CVE-2025-15312
6.6

An improper output sanitization vulnerability in Tanium Appliance could allow attackers to inject malicious content into application outputs. This aff...

Feb 5, 2026
CVE-2026-24439
6.5

Tenda W30E V2 routers with vulnerable firmware lack the X-Content-Type-Options: nosniff header on web management interfaces. This allows attackers to ...

Jan 26, 2026
CVE-2025-6429
6.5

Firefox incorrectly parses URLs in embed tags, rewriting them to youtube.com and bypassing website security checks that restrict embed domains. This a...

Jun 24, 2025
CVE-2024-47224
6.5

A CRLF injection vulnerability in Mitel MiCollab AWV component allows unauthenticated attackers to manipulate URLs to conduct phishing attacks. This a...

Oct 21, 2024
CVE-2025-46703
6.4

This vulnerability allows attackers to inject malicious scripts into BlueSpice wiki pages through the AtMentions extension. When exploited, it enables...

Sep 19, 2025
CVE-2025-48007
6.4

This CVE describes an improper output encoding vulnerability in BlueSpice's Avatars extension that allows cross-site scripting (XSS) attacks. Attacker...

Sep 19, 2025
CVE-2026-28348
6.1

This vulnerability in lxml_html_clean allows attackers to bypass CSS filters by using Unicode escape sequences, potentially enabling cross-site script...

Mar 5, 2026
CVE-2026-25543
6.1

HtmlSanitizer versions before 9.0.892 and 9.1.893-beta fail to sanitize content within template tags when those tags are allowed, potentially enabling...

Feb 4, 2026
CVE-2025-13742
6.1

This vulnerability in pretix allows attackers to inject HTML/Markdown content into emails by using maliciously formatted attendee names. While XSS att...

Nov 27, 2025
CVE-2025-11712
6.1

This vulnerability allows malicious web pages to bypass browser security controls using OBJECT tags when servers don't provide proper content-type hea...

Oct 14, 2025
CVE-2025-24025
6.1

Coolify versions before 4.0.0-beta.380 contain a reflected cross-site scripting (XSS) vulnerability in the tags search functionality. When a search re...

Jan 24, 2025
CVE-2024-6329
5.7

A path encoding vulnerability in GitLab's web interface causes diff rendering failures when viewing file changes. This affects all GitLab CE/EE instan...

Aug 8, 2024
CVE-2025-9127
5.5

A vulnerability in PX Enterprise allows sensitive information to be logged under specific conditions, potentially exposing confidential data. This aff...

Dec 4, 2025
CVE-2025-42896
5.4

SAP BusinessObjects Business Intelligence Platform has a URL parameter injection vulnerability that allows unauthenticated remote attackers to make th...

Dec 9, 2025
CVE-2025-57880
5.4

This CVE describes a cross-site scripting (XSS) vulnerability in BlueSpice's WhoIsOnline extension due to improper output encoding. Attackers can inje...

Sep 19, 2025
CVE-2024-9427
5.4

CVE-2024-9427 is a reflected cross-site scripting (XSS) vulnerability in Koji where unsanitized input allows malicious JavaScript to be executed when ...

Dec 24, 2024
CVE-2024-39929
5.4

This vulnerability in Exim mail servers allows attackers to bypass filename extension filtering by using specially crafted multiline RFC 2231 headers....

Jul 4, 2024
CVE-2025-46583
5.3

A Denial of Service vulnerability exists in ZTE MC889A Pro devices due to insufficient input validation in the SMS interface. Attackers can exploit th...

Oct 27, 2025
CVE-2025-61912
5.3

A vulnerability in python-ldap's escape_dn_chars() function incorrectly escapes null bytes, causing client-side denial of service when constructing DN...

Oct 10, 2025
CVE-2025-25029
4.9

IBM Security Guardium 12.0 contains an improper input escaping vulnerability that allows authenticated privileged users to download arbitrary files fr...

May 28, 2025
CVE-2024-50349
4.7

This vulnerability allows attackers to craft malicious Git repository URLs containing ANSI escape sequences that manipulate terminal output during cre...

Jan 14, 2025
CVE-2025-66488
4.6

This vulnerability in Discourse allows attackers to upload HTML or XML files to S3 storage that can execute scripts in the context of the S3/CDN domai...

Jan 28, 2026
CVE-2026-0818
4.3

This vulnerability in Thunderbird allows attackers to exfiltrate decrypted OpenPGP email contents through CSS injection when users load remote content...

Jan 28, 2026
CVE-2026-22712
4.3

This CVE describes an improper output encoding vulnerability in MediaWiki's ApprovedRevs extension where magic word replacement in ParserAfterTidy all...

Jan 9, 2026
CVE-2025-23377
4.2

This vulnerability allows a high-privileged attacker with local access to inject malicious web scripts or HTML into Dell PowerProtect Data Manager Rep...

Apr 28, 2025
CVE-2025-0083
4.0

This CVE-2025-0083 vulnerability allows unauthorized access to content across user profiles on Android devices due to URI double encoding. It enables ...

Aug 26, 2025
CVE-2023-28362
4.0

This vulnerability in Ruby on Rails allows attackers to inject malicious characters into redirect URLs via the redirect_to method. When downstream ser...

Jan 9, 2025
CVE-2025-12734
3.5

This vulnerability allows authenticated GitLab users to inject malicious HTML content into merge request titles, which could render in other users' di...

Dec 11, 2025
CVE-2025-66548
3.3

This vulnerability in Nextcloud Deck allows attackers to spoof file extensions using Right-to-Left Override (RTLO) characters, tricking users into dow...

Dec 5, 2025
CVE-2025-11085
N/A

A persistent cross-site scripting (XSS) vulnerability in DataMosaix Private Cloud allows attackers to inject malicious JavaScript that executes in use...

Nov 11, 2025

About CWE-116 (CWE-116)

Our database tracks 80 CVEs classified as CWE-116, with 25 rated critical and 25 rated high severity. The average CVSS score for CWE-116 vulnerabilities is 7.5.

External reference: View CWE-116 on MITRE CWE →

Monitor CWE-116 Vulnerabilities

Get alerted when new CWE-116 CVEs affect your infrastructure.

Start Monitoring Free