The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
Volume of CVEs assigned to CWE-117 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
102 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-62948CRITICAL OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefil | Jul 15, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-10745HIGH Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampering-Forging.
This issue affects | Jun 24, 2026 | 7.9 | 34 | NO | NO |
CVE-2026-25548CRITICAL InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7. | Feb 18, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-24308HIGH Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client confi | Mar 7, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-12616MEDIUM The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled, then interpolates that string into three log statements bef | Jun 29, 2026 | 6.9 | 30 | NO | NO |
CVE-2015-10011CRITICAL A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the file resolverapi/endpoints.py. The manipulation leads to improp | Jan 2, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-34478HIGH Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CR | Apr 10, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-45565HIGH Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is th | Jun 10, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-9016MEDIUM The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including, | Jun 6, 2026 | 5.3 | 27 | NO | NO |
CVE-2026-5078MEDIUM Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizi | Jun 3, 2026 | 5.3 | 27 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.