CWE-116: CWE-116
Yearly Trend
Top Affected Vendors
All CWE-116 CVEs (80)
An improper output sanitization vulnerability in Tanium Appliance could allow attackers to inject malicious content into application outputs. This aff...
Feb 5, 2026Tenda W30E V2 routers with vulnerable firmware lack the X-Content-Type-Options: nosniff header on web management interfaces. This allows attackers to ...
Jan 26, 2026Firefox incorrectly parses URLs in embed tags, rewriting them to youtube.com and bypassing website security checks that restrict embed domains. This a...
Jun 24, 2025A CRLF injection vulnerability in Mitel MiCollab AWV component allows unauthenticated attackers to manipulate URLs to conduct phishing attacks. This a...
Oct 21, 2024This vulnerability allows attackers to inject malicious scripts into BlueSpice wiki pages through the AtMentions extension. When exploited, it enables...
Sep 19, 2025This CVE describes an improper output encoding vulnerability in BlueSpice's Avatars extension that allows cross-site scripting (XSS) attacks. Attacker...
Sep 19, 2025This vulnerability in lxml_html_clean allows attackers to bypass CSS filters by using Unicode escape sequences, potentially enabling cross-site script...
Mar 5, 2026HtmlSanitizer versions before 9.0.892 and 9.1.893-beta fail to sanitize content within template tags when those tags are allowed, potentially enabling...
Feb 4, 2026This vulnerability in pretix allows attackers to inject HTML/Markdown content into emails by using maliciously formatted attendee names. While XSS att...
Nov 27, 2025This vulnerability allows malicious web pages to bypass browser security controls using OBJECT tags when servers don't provide proper content-type hea...
Oct 14, 2025Coolify versions before 4.0.0-beta.380 contain a reflected cross-site scripting (XSS) vulnerability in the tags search functionality. When a search re...
Jan 24, 2025A path encoding vulnerability in GitLab's web interface causes diff rendering failures when viewing file changes. This affects all GitLab CE/EE instan...
Aug 8, 2024A vulnerability in PX Enterprise allows sensitive information to be logged under specific conditions, potentially exposing confidential data. This aff...
Dec 4, 2025SAP BusinessObjects Business Intelligence Platform has a URL parameter injection vulnerability that allows unauthenticated remote attackers to make th...
Dec 9, 2025This CVE describes a cross-site scripting (XSS) vulnerability in BlueSpice's WhoIsOnline extension due to improper output encoding. Attackers can inje...
Sep 19, 2025CVE-2024-9427 is a reflected cross-site scripting (XSS) vulnerability in Koji where unsanitized input allows malicious JavaScript to be executed when ...
Dec 24, 2024This vulnerability in Exim mail servers allows attackers to bypass filename extension filtering by using specially crafted multiline RFC 2231 headers....
Jul 4, 2024A Denial of Service vulnerability exists in ZTE MC889A Pro devices due to insufficient input validation in the SMS interface. Attackers can exploit th...
Oct 27, 2025A vulnerability in python-ldap's escape_dn_chars() function incorrectly escapes null bytes, causing client-side denial of service when constructing DN...
Oct 10, 2025IBM Security Guardium 12.0 contains an improper input escaping vulnerability that allows authenticated privileged users to download arbitrary files fr...
May 28, 2025This vulnerability allows attackers to craft malicious Git repository URLs containing ANSI escape sequences that manipulate terminal output during cre...
Jan 14, 2025This vulnerability in Discourse allows attackers to upload HTML or XML files to S3 storage that can execute scripts in the context of the S3/CDN domai...
Jan 28, 2026This vulnerability in Thunderbird allows attackers to exfiltrate decrypted OpenPGP email contents through CSS injection when users load remote content...
Jan 28, 2026This CVE describes an improper output encoding vulnerability in MediaWiki's ApprovedRevs extension where magic word replacement in ParserAfterTidy all...
Jan 9, 2026This vulnerability allows a high-privileged attacker with local access to inject malicious web scripts or HTML into Dell PowerProtect Data Manager Rep...
Apr 28, 2025This CVE-2025-0083 vulnerability allows unauthorized access to content across user profiles on Android devices due to URI double encoding. It enables ...
Aug 26, 2025This vulnerability in Ruby on Rails allows attackers to inject malicious characters into redirect URLs via the redirect_to method. When downstream ser...
Jan 9, 2025This vulnerability allows authenticated GitLab users to inject malicious HTML content into merge request titles, which could render in other users' di...
Dec 11, 2025This vulnerability in Nextcloud Deck allows attackers to spoof file extensions using Right-to-Left Override (RTLO) characters, tricking users into dow...
Dec 5, 2025A persistent cross-site scripting (XSS) vulnerability in DataMosaix Private Cloud allows attackers to inject malicious JavaScript that executes in use...
Nov 11, 2025About CWE-116 (CWE-116)
Our database tracks 80 CVEs classified as CWE-116, with 25 rated critical and 25 rated high severity. The average CVSS score for CWE-116 vulnerabilities is 7.5.
External reference: View CWE-116 on MITRE CWE →
Monitor CWE-116 Vulnerabilities
Get alerted when new CWE-116 CVEs affect your infrastructure.
Start Monitoring Free