Skip to main content

CWE archive

CWE-116 CVEs

Programmatic archive

475 CVEs tagged with CWE-11664 Critical, 155 High, 215 Medium, 41 Low, 0 Unrated.

CVE-2025-57880

Published Sep 19, 2025

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceWhoIsOnline) allows Cross-Site Scripting (XSS). This issue affects BlueSpic…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48007

Published Sep 19, 2025

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: f…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46703

Published Sep 19, 2025

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:AtMentions) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8276

Published Sep 16, 2025

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, Improper Neutralization of Special Elements i…

CVSS 4.3 · Medium

CVE-2025-55730

Published Sep 9, 2025

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping o…

CVSS 10.0 · Critical

CVE-2025-55729

Published Sep 9, 2025

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping o…

CVSS 10.0 · Critical

CVE-2025-0083

Published Aug 26, 2025

In multiple locations, there is a possible way to access content across user profiles due to URI double encoding. This could lead to local information disclosure with no additiona…

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-58266

Published Jul 27, 2025

The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may facilitate command injection.

CVSS 3.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-34141

Published Jul 22, 2025

A reflected cross-site scripting (XSS) vulnerability exists in ETQ Reliance CG (legacy) platform within the `SQLConverterServlet` component. This vulnerability requires user inter…

CVSS 5.1 · Medium

CVE-2025-6429

Published Jun 24, 2025

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49013

Published Jun 9, 2025

WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe us…

CVSS 9.9 · Critical

CVE-2025-48062

Published Jun 9, 2025

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25029

Published May 28, 2025

IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5271

Published May 27, 2025

Previewing a response in Devtools ignored CSP headers, which could have allowed content injection attacks. This vulnerability was fixed in Firefox 139 and Thunderbird 139.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1308

Published May 19, 2025

A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions.

CVSS 8.4 · High

CVE-2025-47280

Published May 13, 2025

Umbraco Forms is a form builder that integrates with the Umbraco content management system. Starting in the 7.x branch and prior to versions 13.4.2 and 15.1.2, the 'Send email' wo…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-56524

Published May 12, 2025

Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by adding a special character to the request.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-46340

Published May 5, 2025

Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, due to an oversight in the validation performed in `UrlPrevie…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32974

Published Apr 30, 2025

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAr…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24338

Published Apr 30, 2025

A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivileged) attacker to execute arbitrary client-side…

CVSS 7.1 · High

CVE-2025-46347

Published Apr 29, 2025

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extens…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 475 CVEsPage 7 of 19