Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exi
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, ca
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra a
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass.
Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLa
Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions
CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, t
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing t
NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper en
GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled f
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attac
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) rende
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc
Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. Th
Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.
FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an au
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML inje
** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 fi
Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia
When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function ca
Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/
PRSD detection denial of service
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in l
Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via u
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a
HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validatio
openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to
gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attacker
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 1
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/
GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a tech
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e
A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering pa
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, sever
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the l
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, un
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto
URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API requ
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content t
Frequently Asked Questions
What is CWE-116?
CWE-116 (CWE-116) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-116?
There are 553 CVE records associated with CWE-116 in our database. Of these, 64 are critical severity, 155 are high severity, and 227 are medium severity.
How can I protect against CWE-116 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-116 using AI-powered security agents.
Detect CWE-116 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-116 vulnerabilities across your infrastructure.
Get Started