YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc
ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vuln
GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user c
mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-or
Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authe
Tanium addressed an improper output sanitization vulnerability in Tanium Appliance.
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Option
A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function o
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inj
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed t
MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode conten
Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca
A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks.
Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee0
Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a content-type confusion vulnerability in the adm
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th
lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th
Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in
LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct
Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that h
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template en
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It
pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered e
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute wit
CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Dif
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi
A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,
Docmost is open-source collaborative wiki and documentation software. In versions 0.3.0 through 0.23.2, Mermaid code blo
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Sc
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulner
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item
lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML in
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation com
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the
Frequently Asked Questions
What is CWE-116?
CWE-116 (CWE-116) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-116?
There are 553 CVE records associated with CWE-116 in our database. Of these, 64 are critical severity, 155 are high severity, and 227 are medium severity.
How can I protect against CWE-116 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-116 using AI-powered security agents.
Detect CWE-116 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-116 vulnerabilities across your infrastructure.
Get Started