CWE-791Base

Incomplete Filtering of Special Elements

Incomplete in the CWE catalog · 37 CVEs mapped

37
CVEs mapped
5.3
Median CVSS
What it is

The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

Recent examples
none
CVE-2026-86206

CVE-2026-86206 - UNKNOWN Severity Vulnerability

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

no explanation yet
0%
epss
4.7cvss
CVE-2026-78140

CVE-2026-78140 - MEDIUM Severity Vulnerability

A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executing a manipulation can lead to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been published and may be used.

MEDIUMno explanation yet
0%
epss
6.3cvss
CVE-2026-75979

CVE-2026-75979 - MEDIUM Severity Vulnerability

A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sqlText results in improper neutralization of special elements used in a template engine. The attack can be executed remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-791
Abstraction
Base
Structure
Simple
Status
Incomplete