CWE-792Variant

Incomplete Filtering of One or More Instances of Special Elements

Incomplete in the CWE catalog · 5 CVEs mapped

5
CVEs mapped
5.2
Median CVSS
What it is

The product receives data from an upstream component, but does not completely filter one or more instances of special elements before sending it to a downstream component.

Recent examples
8.7cvss
CVE-2025-12758

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength()…

⚡ A sneaky oversight in string length validation could let attackers slip massive inputs right past the gates! Think of it like a restaurant that forgets to check the portion sizes on the plates — if they don't get it right, diners might walk away stuffed or, worse, cause a food fight when their orders overflow! This vulnerability could allow an attacker to submit input strings much longer than your application is ready to handle. The fallout? You could end up with data truncation in your databases, buffer overflows in system components, or even a denial-of-service situation that brings your app to its knees!

HIGH
1%
epss
7.7cvss
CVE-2025-47779

Using malformed From header can forge identity with ";" or NULL in name portion

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, SIP requests of the type MESSAGE (RFC 3428) authentication do not get proper alignment. An authenticated attacker can spoof any user identity to send spam messages to the user with their authorization token. Abuse of this security issue allows authenticated attackers to send fake chat messages can be spoofed to appear to come from trusted entities. Even administrators who follow Security best practices and Security Considerations can be impacted. Therefore, abuse can lead to spam and enable social engineering, phishing and similar attacks. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.

HIGHno explanation yet
1%
epss
5.2cvss
CVE-2023-25608

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1…

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-W2 7.2.0 through 7.2.1, 7.0.3 through 7.0.5, 7.0.0 through 7.0.1, 6.4 all versions, 6.2 all versions, 6.0 all versions; FortiAP-C 5.4.0 through 5.4.4, 5.2 all versions; FortiAP 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions, 6.0 all versions; FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to read arbitrary files via specially crafted command arguments.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-792
Abstraction
Variant
Structure
Simple
Status
Incomplete