Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-116

MITRE ↗

CWE-116

64
CRITICAL
155
HIGH
227
MEDIUM
29
LOW
515 CVEs · Page 5/11
6.3
CVE-2025-23207

KaTeX is a fast, easy-to-use JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted math

6.1
CVE-2025-24025

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0

6.1
CVE-2025-47280

Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch a

6.1
CVE-2025-11712

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encou

6.1
CVE-2021-47694

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site

6.1
CVE-2025-63785

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2

6.1
CVE-2025-13742

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used

5.7
CVE-2025-4084

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user int

5.5
CVE-2025-9127

A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.

5.4
CVE-2024-52891

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious inf

5.4
CVE-2023-35894

IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by

5.4
CVE-2025-32074

Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Confirm Account Extension

5.4
CVE-2021-25262

Yandex Browser for Android prior to version 21.3.0 allows remote attackers to perform IDN homograph attack.

5.4
CVE-2025-57880

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) all

5.4
CVE-2025-42896

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through

5.3
CVE-2024-56277

Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: fr

5.3
CVE-2024-56473

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log f

5.3
CVE-2024-49355

IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enab

5.3
CVE-2024-50629

Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1

5.3
CVE-2025-30657

An Improper Encoding or Escaping of Output vulnerability in the Sampling Route Record Daemon (SRRD) of Juniper Networks

5.3
CVE-2021-25254

Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.

5.3
CVE-2025-61912

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn

5.3
CVE-2025-46583

There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the inpu

4.9
CVE-2025-25029

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of

4.7
CVE-2024-50349

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-

4.3
CVE-2025-3942

Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niaga

4.3
CVE-2025-8276

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi

4.3
CVE-2025-0607

Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affe

4.2
CVE-2025-23377

Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output

4.0
CVE-2023-28362

The redirect_to method in Rails allows provided values to contain characters which are not legal in an HTTP header value

4.0
CVE-2025-0083

In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This c

3.5
CVE-2025-30345

An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user i

3.5
CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 1

3.3
CVE-2025-66548

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra

3.2
CVE-2024-58266

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa

CVE-2025-1795

During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded t

CVE-2025-32072

Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki Core - Feed Utils allows Web

CVE-2025-32078

Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - Version Compare Extension

CVE-2025-1308

A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions.

CVE-2025-34141

A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverte

CVE-2025-11085

A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in t

10.0
CVE-2023-47143

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, cau

9.8
CVE-2024-31866

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or ma

9.8
CVE-2024-38474

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts i

9.8
CVE-2024-55663

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc

9.6
CVE-2024-35225

Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authen

9.4
CVE-2024-1874

In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array

9.3
CVE-2024-22199

This package provides universal methods to use multiple template engines with the Fiber web framework using the Views in

9.1
CVE-2024-38475 KEV

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to fi

8.8
CVE-2024-45498

Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an

Frequently Asked Questions

What is CWE-116?

CWE-116 (CWE-116) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-116?

There are 553 CVE records associated with CWE-116 in our database. Of these, 64 are critical severity, 155 are high severity, and 227 are medium severity.

How can I protect against CWE-116 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-116 using AI-powered security agents.

Detect CWE-116 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-116 vulnerabilities across your infrastructure.

Get Started