The product does not properly filter, remove, quote, or otherwise manage the invalid use of special elements in user-controlled input, which could cause adverse effect on its behavior and integrity.
Volume of CVEs assigned to CWE-159 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21707MEDIUM In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If | Nov 29, 2021 | 5.3 | 32 | NO | NO |
CVE-2020-1653HIGH On Juniper Networks Junos OS devices, a stream of TCP packets sent to the Routing Engine (RE) may cause mbuf leak which can lead to Flexible PIC Concentrator (FPC) crash or the sys | Jul 17, 2020 | 7.5 | 26 | NO | NO |
CVE-2026-2636MEDIUM This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. Th | Feb 25, 2026 | 5.5 | 25 | NO | NO |
CVE-2019-9505CRITICAL The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration f | May 8, 2019 | 9.8 | 25 | NO | NO |
ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to code execution when a ProxyCommand | Oct 6, 2025 | 3.6 | 24 | NO | NO |
CVE-2026-35536MEDIUM In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characte | Apr 3, 2026 | 5.3 | 22 | NO | NO |
CVE-2024-51500HIGH Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFF | Nov 4, 2024 | 7.5 | 22 | NO | NO |
CVE-2026-29106MEDIUM SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the value of the return_id request par | Mar 19, 2026 | 6.1 | 21 | NO | NO |
CVE-2021-42375MEDIUM An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific character | Nov 15, 2021 | 5.5 | 20 | NO | NO |
CVE-2020-29022MEDIUM Failure to Sanitize host header value on output in the GateManager Web server could allow an attacker to conduct web cache poisoning attacks. This issue affects Secomea GateManager | Feb 16, 2021 | 5.3 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.