CWE-116
Improper Encoding or Escaping of Output
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 17 of 17- CVE-2026-47188—EPSS 0%9 h ago
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the latest release suppresses mentions in several moderation commands, but /unban and /unwarn still echo user-controlled reas
- CVE-2026-47175—EPSS 0%9 h ago
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, several moderation commands echo user-controlled reason text in public bot replies without disabling mention parsing. A moder
- CVE-2026-45011High· 7.3EPSS 0%15 h ago
Apostrophe has stored XSS via javascript: URL in Image Widget Link
npm - CVE-2026-20245High· 7.8KEVEPSS 0%20 h ago
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
- CVE-2022-24682Medium· 6.1KEVEPSS 89%20 h ago
Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability
- CVE-2024-38475Critical· 9.1KEVEPSS 94%20 h ago
Apache HTTP Server Improper Escaping of Output Vulnerability
- CVE-2022-42948Critical· 9.8KEVEPSS 22%20 h ago
Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
- CVE-2026-54133Critical· 9.820 h ago
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlle
- CVE-2026-48485—21 h ago
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, unbanning, unwarning, kicking, muting, and unmuting, but stored warning reasons are still printed by /warns without mentio
- CVE-2026-47173—EPSS 0%21 h ago
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a normal user can create a ticket with a reason containing @everyone, @here, user mentions, or role mentions. When the ticket
- CVE-2026-47171—EPSS 0%1 d ago
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a normal user can create a reminder whose message contains @everyone or @here. When the reminder triggers, the bot sends the
- CVE-2026-42558High· 7.6EPSS 0%1 d ago
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the Xibo CMS allows users
- CVE-2026-53693—EPSS 0%2 d ago
A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HT
- CVE-2026-49472Medium· 5.3EPSS 0%2 d ago
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable
- CVE-2026-8795High· 7.8EPSS 0%3 d ago
A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML template via Go's text/t
- CVE-2026-46496—EPSS 0%4 d ago
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
npm - CVE-2025-0607Medium· 4.3EPSS 0%7 d ago
Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affects Logo Cloud: before 2.57.
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.