The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.
Volume of CVEs assigned to CWE-76 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1883MEDIUM This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a s | Mar 14, 2024 | 6.1 | 49 | NO | NO |
CVE-2024-34359CRITICAL llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The ` | May 14, 2024 | 9.6 | 47 | NO | NO |
CVE-2023-0493HIGH Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
| Jan 26, 2023 | 8.8 | 41 | NO | YES |
CVE-2026-28292CRITICAL `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes | Mar 10, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-55723HIGH When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGIN | Jul 15, 2026 | 8.3 | 38 | NO | NO |
CVE-2026-11311MEDIUM When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. | Jun 17, 2026 | 6.5 | 32 | NO | NO |
CVE-2024-2952CRITICAL BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the ` | Apr 10, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-4897HIGH parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311 | Jul 2, 2024 | 8.4 | 23 | NO | NO |
CVE-2024-1882HIGH This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting the PaperCut NG/ | Mar 14, 2024 | 7.2 | 20 | NO | NO |
CVE-2023-1149MEDIUM Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0. | Mar 2, 2023 | 5.4 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.