The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Volume of CVEs assigned to CWE-116 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
475 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38475CRITICAL Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the se | Jul 1, 2024 | 9.1 | 97 | YES | YES |
CVE-2022-36446CRITICAL software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. | Jul 25, 2022 | 9.8 | 94 | NO | YES |
CVE-2026-20245HIGH A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, | Jun 4, 2026 | 7.8 | 88 | YES | NO |
CVE-2022-30781HIGH Gitea before 1.16.7 does not escape git fetch remote. | May 16, 2022 | 7.5 | 86 | NO | YES |
CVE-2022-24682MEDIUM An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attack | Feb 9, 2022 | 6.1 | 82 | YES | YES |
CVE-2021-31806MEDIUM An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the pro | May 27, 2021 | 6.5 | 81 | NO | YES |
CVE-2022-42948CRITICAL Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the C | Mar 24, 2023 | 9.8 | 70 | YES | NO |
CVE-2022-36099HIGH XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 a | Sep 8, 2022 | 8.8 | 70 | NO | NO |
CVE-2022-36100HIGH XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and | Sep 8, 2022 | 8.8 | 69 | NO | NO |
CVE-2023-32071CRITICAL XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the r | May 9, 2023 | 9.0 | 67 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.