CWE-116

CWE-116 · 10 records · 8 with a public proof-of-concept

Records the NVD classes under CWE-116, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-90999

    Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry …

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.1CVE-2026-61784public PoC

    xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializing its sanitized output. In attributeString() (XHTMLPurifier.…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.1CVE-2026-58504public PoC

    draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the draw.io origin when selected cells are processed by TextFormatPanel.addF…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.4CVE-2026-13407

    The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notification emails, allowing unauthenticated attackers to inject arbi…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 4.9CVE-2026-63329public PoC

    Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the authenticated userna…

    AI risk analysis on Exploit-DB.ai →

  6. UNSCOREDCVE-2026-63208public PoC

    Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails, Zammad logs the error including the authentication token used to access the mailbox. The system attempts to hide this token in the log, bu…

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-55214public PoC

    GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the stored cross-site scripting pa…

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-82409public PoC

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The …

    AI risk analysis on Exploit-DB.ai →

  9. UNSCOREDCVE-2026-95659public PoC

    MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-themed AnalystData thread vi…

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-77404public PoC

    RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string instead of encoding them as URL query parameters with url.Values. If an a…

    AI risk analysis on Exploit-DB.ai →