The product does not neutralize or incorrectly neutralizes delimiters.
Volume of CVEs assigned to CWE-140 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-47162HIGH Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pa | Jun 11, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-6322HIGH fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an | May 5, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-33456HIGH Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Live | Apr 10, 2026 | 7.6 | 30 | NO | NO |
CVE-2023-31208HIGH Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for au | May 17, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-6157HIGH Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authori | Nov 22, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-6156HIGH Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command executi | Nov 22, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-32918HIGH Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an a | Jul 4, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-38865HIGH Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatu | Apr 10, 2025 | 8.8 | 23 | NO | NO |
CVE-2023-38488HIGH Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites that might have potential attackers | Jul 27, 2023 | 8.8 | 23 | NO | NO |
CVE-2026-33457MEDIUM Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted s | Apr 10, 2026 | 6.3 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.