CWE-93: CWE-93

25
Total CVEs
0
Critical
14
High
7.2
Avg CVSS

Yearly Trend

2026
7
2025
10
2024
5
2022
1
2021
2

Top Affected Vendors

1 Qnap 2
2 Restsharp 1
3 Catchethq 1
4 Fortinet 1
5 Comfy 1
6 Kentico 1
7 Apache 1
8 Cisco 1
9 Linuxcontainers 1
10 Microweber 1

All CWE-93 CVEs (25)

CVE-2025-28357
8.8

A CRLF injection vulnerability in Neto CMS allows attackers to inject malicious HTTP headers through crafted requests, potentially leading to arbitrar...

Oct 1, 2025
CVE-2021-39172
8.8

CVE-2021-39172 is a critical newline injection vulnerability in Cachet status page systems that allows authenticated users (both regular users and adm...

Aug 27, 2021
CVE-2026-23953
8.7

This vulnerability allows users in the 'incus' group to inject newlines into container environment variables, enabling arbitrary command execution on ...

Jan 22, 2026
CVE-2026-1714
8.6

This vulnerability allows unauthenticated attackers to abuse the ShopLentor WordPress plugin as an email relay. Attackers can send arbitrary emails wi...

Feb 18, 2026
CVE-2025-59151
8.2

Pi-hole Admin Interface before version 6.3 is vulnerable to CRLF injection, allowing attackers to inject arbitrary HTTP response headers by manipulati...

Oct 27, 2025
CVE-2024-20337
8.2

This CRLF injection vulnerability in Cisco Secure Client's SAML authentication allows unauthenticated attackers to execute arbitrary script code in us...

Mar 6, 2024
CVE-2026-22777
7.5

ComfyUI-Manager extension versions before 3.39.2 and 4.0.5 contain an injection vulnerability where attackers can manipulate HTTP query parameters to ...

Jan 10, 2026
CVE-2025-27111
7.5

CVE-2025-27111 is a log injection vulnerability in Rack's Sendfile middleware that allows attackers to inject escape sequences (like newlines) via the...

Mar 4, 2025
CVE-2024-48867
7.5

This CRLF injection vulnerability in QNAP operating systems allows remote attackers to inject carriage return and line feed sequences, potentially mod...

Dec 6, 2024
CVE-2024-1226
7.5

This CVE describes an HTTP header injection vulnerability where unvalidated user input is included in HTTP headers, allowing attackers to manipulate H...

Mar 12, 2024
CVE-2022-0666
7.5

This CVE describes a CRLF injection vulnerability in Microweber CMS that allows attackers to inject carriage return and line feed characters into HTTP...

Feb 18, 2022
CVE-2021-31164
7.5

Apache Unomi versions before 1.5.5 are vulnerable to CRLF log injection due to improper escaping in log statements. This allows attackers to inject ma...

May 4, 2021
CVE-2025-6175
7.2

This CRLF injection vulnerability in DECE Software Geodi allows attackers to inject malicious HTTP headers and split HTTP responses, potentially enabl...

Jul 29, 2025
CVE-2024-53693
7.1

This CRLF injection vulnerability in QNAP operating systems allows attackers with user access to manipulate application data by injecting carriage ret...

Mar 7, 2025
CVE-2022-50682
6.5

A CRLF injection vulnerability in Kentico Xperience's routing engine allows attackers to manipulate URL query string redirects through improper encodi...

Dec 18, 2025
CVE-2025-67735
6.5

This CVE describes a CRLF injection vulnerability in Netty's HttpRequestEncoder that allows request smuggling. Attackers can inject malicious content ...

Dec 16, 2025
CVE-2025-56007
6.5

This CRLF injection vulnerability in KeeneticOS allows attackers to add unauthorized administrative users by tricking victims into visiting a maliciou...

Oct 23, 2025
CVE-2025-48388
6.5

FreeScout help desk software prior to version 1.8.178 has an input validation vulnerability where special characters like carriage returns, newlines, ...

May 29, 2025
CVE-2024-45302
6.1

RestSharp versions before 112.0.0 are vulnerable to CRLF injection in HTTP headers, allowing attackers to inject malicious headers or smuggle HTTP req...

Aug 29, 2024
CVE-2026-1467
5.8

This CRLF injection vulnerability in libsoup allows attackers to inject malicious HTTP headers or request bodies when an HTTP proxy is configured. It ...

Jan 27, 2026
CVE-2024-45597
5.3

CVE-2024-45597 is an HTTP request injection vulnerability in Pluto (a Lua 5.4 superset) where user-controlled values passed to http.request headers ca...

Sep 10, 2024
CVE-2025-54972
4.3

This CRLF injection vulnerability in Fortinet FortiMail allows attackers to inject HTTP headers into server responses by tricking users into clicking ...

Nov 18, 2025
CVE-2026-1299
N/A

This vulnerability in Python's email module allows header injection when serializing email messages. Attackers can inject malicious headers by exploit...

Jan 23, 2026
CVE-2025-11468
N/A

This vulnerability in Python's email header parsing allows header injection when processing user-controlled email addresses containing specific commen...

Jan 20, 2026
CVE-2025-15282
N/A

This vulnerability in Python's urllib.request.DataHandler allows attackers to inject HTTP headers through newline characters in data URL mediatypes. T...

Jan 20, 2026

About CWE-93 (CWE-93)

Our database tracks 25 CVEs classified as CWE-93, with 0 rated critical and 14 rated high severity. The average CVSS score for CWE-93 vulnerabilities is 7.2.

External reference: View CWE-93 on MITRE CWE →

Monitor CWE-93 Vulnerabilities

Get alerted when new CWE-93 CVEs affect your infrastructure.

Start Monitoring Free