CWE-116
CVEs classified under CWE-116, newest first.
109 CVEsRSS
GHSA-hc76-7mpc-qjqhMedium· 5.7ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
GHSA-pppj-hq3g-57pjHighJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
CVE-2026-64647MediumNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
CVE-2026-59895Medium· 6.1Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-59727LowAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-15809High· 7.8A flaw was found in CRI-O
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME e…
CVE-2026-50659Medium· 6.5.NET Spoofing Vulnerability
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-45710Low· 3.5FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
CVE-2026-49844Medium· 6.3PoCImproper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.…
CVE-2026-55659High· 7.7Grist is spreadsheet software using Python as its formula language
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-si…
GHSA-cwv4-h3j5-w3cfLow· 3.7rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
CVE-2026-54893Low· 2.1URL path injection in the Microsoft Graph adapter of Swoosh
URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API request URL by interpolating the sender's email address into the URL path (/users/{from}/sendMail) without percent-encodi…
CVE-2026-35346Low· 3.3comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
CVE-2026-35366Medium· 4.4printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
GHSA-jf6w-2mvx-633jMedium· 6.1justhtml: to_markdown() code-span blank-line breakout enables XSS
justhtml: to_markdown() code-span blank-line breakout enables XSS
GHSA-v772-658q-978pLowDuplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
CVE-2026-56379High· 8.1ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector G…
CVE-2026-44913Medium· 7.2Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL
CVE-2026-12048Critical· 9.3Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths
Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside E…
CVE-2026-12047Low· 3.5HTML injection in pgAdmin 4's cloud deployment module
HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception…
GHSA-9wxg-vf3r-56hcLow· 3.3OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
GHSA-38x9-25wx-7fg2HighHeimdall: IP Spoofing via Unvalidated Forwarding Headers
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
GHSA-crmm-hgp2-wgrpMedium· 4.2Laravel Framework: Temporary Signed URL Path Confusion
Laravel Framework: Temporary Signed URL Path Confusion
CVE-2026-54013High· 7.6Open WebUI: Stored XSS to Account Takeover via Model Profile Images
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
CVE-2026-54287Medium· 5.3hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
CVE-2026-52846Medium· 4.2Caddy: stripHTML template function bypass
Caddy: stripHTML template function bypass
CVE-2026-54133Critical· 9.8jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)
A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…
GHSA-6jq6-x4cx-qvcmMediumFirefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)
Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)
CVE-2026-44311Medium· 5.4Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
CVE-2026-47768Medium· 5.5nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)