CWE-117: CWE-117

33
Total CVEs
2
Critical
7
High
6.1
Avg CVSS

Yearly Trend

2026
3
2025
20
2024
7
2023
3

Top Affected Vendors

1 Ibm 7
2 Splunk 3
3 Advanced Intrusion Detection Environment Project 1
4 Litellm 1
5 Iterm2 1
6 Fortinet 1
7 Trianglemicroworks 1
8 Djangoproject 1
9 Microsoft 1
10 Kitsada8621 1

All CWE-117 CVEs (33)

CVE-2023-46321
9.8

This vulnerability in iTerm2 allows command injection through malicious x-man-page URLs. Attackers can execute arbitrary commands on the system by cra...

Oct 23, 2023
CVE-2024-0095
9.0

CVE-2024-0095 is a log injection vulnerability in NVIDIA Triton Inference Server that allows attackers to inject forged logs and executable commands b...

Jun 13, 2024
CVE-2024-25047
8.6

IBM Cognos Analytics versions 11.2.0-11.2.4 and 12.0.0-12.0.2 have improper input validation in application logging, allowing injection attacks. This ...

May 2, 2024
CVE-2023-3997
8.6

CVE-2023-3997 is a log file poisoning vulnerability in Splunk SOAR where attackers can inject malicious ANSI escape sequences through web requests. Wh...

Jul 31, 2023
CVE-2023-32712
8.6

This vulnerability allows attackers to inject ANSI escape codes into Splunk log files, which could lead to code execution in vulnerable terminal appli...

Jun 1, 2023
CVE-2025-57564
8.2

CVE-2025-57564 allows unauthenticated attackers to inject arbitrary log entries into CubeAPM production systems via the /api/logs/insert/elasticsearch...

Oct 7, 2025
CVE-2025-54813
7.5

This vulnerability in Apache Log4cxx's JSONLayout allows attackers to inject non-printable characters into log messages, which aren't properly escaped...

Aug 22, 2025
CVE-2024-9606
7.5

This vulnerability in berriai/litellm's logging function only masks the first 5 characters of API keys, exposing nearly the entire secret key in appli...

Mar 20, 2025
CVE-2024-47083
7.5

The Power Platform Terraform Provider versions before 3.0.0 expose service principal client_secret values in logs due to improper masking. This allows...

Sep 25, 2024
CVE-2025-58580
6.5

This vulnerability allows attackers to create arbitrary log entries via an unvalidated API endpoint. Attackers can falsify or dilute logs, compromisin...

Oct 6, 2025
CVE-2024-7696
6.3

This vulnerability allows authenticated attackers to tamper with audit logs or perform denial-of-service attacks on AXIS Camera Station servers by cra...

Jan 7, 2025
CVE-2025-36159
6.2

IBM Concert versions 1.0.0 through 2.0.0 have a log file forgery vulnerability where local users can manipulate log entries to impersonate other users...

Nov 20, 2025
CVE-2025-54389
6.2

CVE-2025-54389 is an improper output neutralization vulnerability in AIDE (Advanced Intrusion Detection Environment) that allows local attackers to hi...

Aug 14, 2025
CVE-2026-1337
5.4

This vulnerability allows cross-site scripting (XSS) attacks when Neo4j query logs containing insufficiently escaped unicode characters are opened in ...

Feb 6, 2026
CVE-2024-52891
5.4

This vulnerability in IBM Concert Software allows authenticated users to inject malicious content into log files or extract sensitive information from...

Jan 7, 2025
CVE-2025-66577
5.3

This vulnerability in cpp-httplib allows attackers to spoof client IP addresses by sending malicious X-Forwarded-For or X-Real-IP headers. This can po...

Dec 5, 2025
CVE-2025-20384
5.3

An unauthenticated attacker can inject ANSI escape codes into Splunk log files via the /en-US/static/ endpoint, allowing them to manipulate or obfusca...

Dec 3, 2025
CVE-2025-36081
5.3

IBM Concert Software versions 1.0.0 through 2.0.0 contain a log injection vulnerability (CWE-117) that allows authenticated users to modify system log...

Oct 28, 2025
CVE-2025-59476
5.3

This vulnerability allows attackers who can control log message content in Jenkins to insert line break characters followed by forged log messages. Th...

Sep 17, 2025
CVE-2024-52962
5.3

An unauthenticated remote attacker can inject malicious content into FortiAnalyzer and FortiManager logs via crafted login requests. This log pollutio...

Apr 8, 2025
CVE-2024-12580
5.3

This CVE describes a log injection vulnerability in LibreChat where unvalidated parameters in download APIs allow attackers to inject malicious conten...

Mar 20, 2025
CVE-2025-23405
5.3

This vulnerability involves improper output neutralization for logs (CWE-117) in DarioHealth medical devices, allowing unauthenticated attackers to in...

Feb 28, 2025
CVE-2024-49355
5.3

IBM OpenPages with Watson versions 8.3 and 9.0 may write improperly neutralized data to server log files when System Tracing is enabled. This could al...

Feb 20, 2025
CVE-2024-56473
5.3

IBM Aspera Shares versions 1.9.0 through 1.10.0 PL6 improperly validate 'Client-IP' headers, allowing attackers to spoof their IP addresses in log fil...

Feb 5, 2025
CVE-2024-8297
5.3

This vulnerability in kitsada8621 Digital Library Management System 1.0 allows attackers to inject malicious content into application logs through the...

Aug 29, 2024
CVE-2023-28952
5.3

IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0 are vulnerable to injection attacks in application logging due to improper sanitization of u...

May 3, 2024
CVE-2025-11537
5.0

Keycloak versions with verbose logging patterns (like 'long') expose sensitive headers including Authorization and Cookie in cleartext logs. Attackers...

Feb 10, 2026
CVE-2023-39461
4.4

This vulnerability in Triangle MicroWorks SCADA Data Gateway allows authenticated remote attackers to write arbitrary files to the system by exploitin...

May 3, 2024
CVE-2025-36625
4.3

This vulnerability allows unauthenticated attackers to manipulate Nessus logging entries by sending specially crafted HTTP requests. It affects Nessus...

Apr 18, 2025
CVE-2025-0754
4.3

This vulnerability in OpenShift Service Mesh allows attackers to inject malicious payloads into HTTP headers, specifically x-forwarded-for, which can ...

Jan 28, 2025
CVE-2024-8334
4.3

This vulnerability allows remote attackers to inject malicious content into application logs through improper output neutralization in Sweet-CMS's Log...

Aug 30, 2024
CVE-2025-12755
4.0

IBM MQ Operator and container images have a log injection vulnerability where log messages aren't properly sanitized before being written to log files...

Feb 17, 2026
CVE-2025-48432
4.0

A log injection vulnerability in Django allows attackers to manipulate HTTP response logging by sending crafted URLs. This could corrupt log files or ...

Jun 5, 2025

About CWE-117 (CWE-117)

Our database tracks 33 CVEs classified as CWE-117, with 2 rated critical and 7 rated high severity. The average CVSS score for CWE-117 vulnerabilities is 6.1.

External reference: View CWE-117 on MITRE CWE →

Monitor CWE-117 Vulnerabilities

Get alerted when new CWE-117 CVEs affect your infrastructure.

Start Monitoring Free