https://pear.php.net/bugs/bug.php?id=10324
Bug #10324 :: Unescaped values on invalid bugs
bugvaluesinvalid
https://advisories.gitlab.com/golang/istio.io/istio/CVE-2026-39350/
Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots | GitLab Advisory...
CVE-2026-39350 Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots: The serviceAccounts and notServiceAccounts fields in...
istioregexinjectionviadots
https://advisories.gitlab.com/composer/froxlor/froxlor/GHSA-gc9w-cc93-rjv8/
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation...
GHSA-gc9w-cc93-rjv8 Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API):...
https://advisories.gitlab.com/gem/govuk_tech_docs/CVE-2024-22048/
govuk_tech_docs vulnerable to unescaped HTML on search results page | GitLab Advisory Database...
CVE-2024-22048 govuk_tech_docs vulnerable to unescaped HTML on search results page: Pages that are indexed in search results have their entire contents...
https://advisories.gitlab.com/composer/thorsten/phpmyfaq/GHSA-pm8c-3qq3-72w7/
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields |...
GHSA-pm8c-3qq3-72w7 phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields: CurrentUser::setTokenData() in...
sql injection
https://packagist.org/packages/luzrain/doctrine-json-unescaped-type
luzrain/doctrine-json-unescaped-type - Packagist.org
Preventing json Doctrine type to escape unicode characters.
doctrinejsontypepackagist
https://advisories.gitlab.com/golang/miniflux.app/v2/CVE-2023-27592/
Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler |...
CVE-2023-27592 Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler: Since v2.0.25, Miniflux will automatically...
https://advisories.gitlab.com/nuget/log4net/CVE-2026-40021/
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML...
CVE-2026-40021 Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters: Apache Log4net's...
https://advisories.gitlab.com/maven/org.apache.logging.log4j/log4j-1.2-api/CVE-2026-34479/
Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0...
CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters: The Log4j1XmlLayout...
https://lists.w3.org/Archives/Public/public-html-bugzilla/2010Apr/0425.html
[Bug 6670] Allow unescaped &s, at least in attributes that accept URLs from bugzilla@jessica.w3.org...
https://advisories.gitlab.com/golang/github.com/beego/beego/CVE-2025-30223/
Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input |...
CVE-2025-30223 Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input: A Cross-Site Scripting (XSS) vulnerability...
https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99136
Unescaped " escape with backslash issue | DevCentral
escapebackslashissuedevcentral
https://advisories.gitlab.com/gem/prosemirror_to_html/CVE-2025-64501/
Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values | GitLab Advisory...
CVE-2025-64501 Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values: The prosemirror_to_html gem is vulnerable to Cross-Site...
cross site scripting
https://advisories.gitlab.com/pypi/wger/CVE-2026-40353/
wger has Stored XSS via Unescaped License Attribution Fields | GitLab Advisory Database (GLAD)
CVE-2026-40353 wger has Stored XSS via Unescaped License Attribution Fields: The AbstractLicenseModel.attribution_link property in wger/utils/models.py...
https://spring.io/security/cve-2026-22744/
CVE-2026-22744: RediSearch Query via Unescaped TAG Filter Values in RedisVectorStore
Level up your Java code and explore what Spring can do for you.
https://advisories.gitlab.com/composer/wwbn/avideo/GHSA-gmpc-fxg2-vcmq/
AVideo has Stored XSS via Unescaped Menu Item Fields in TopMenu Plugin | GitLab Advisory Database...
GHSA-gmpc-fxg2-vcmq AVideo has Stored XSS via Unescaped Menu Item Fields in TopMenu Plugin: The TopMenu plugin renders menu item fields (icon classes, URLs,...
https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99134
Unescaped " escape with backslash issue | DevCentral
escapebackslashissuedevcentral
https://advisories.gitlab.com/maven/net.sourceforge.pmd/pmd-core/CVE-2026-28338/
PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages |...
CVE-2026-28338 PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages: PMD's vbhtml and yahtml report formats insert...
https://advisories.gitlab.com/pypi/praisonaiagents/CVE-2026-34937/
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution | GitLab Advisory...
CVE-2026-34937 PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution: run_python() in praisonai constructs a shell command string by...
shellinjectionrun
https://advisories.gitlab.com/pypi/gi-docgen/CVE-2025-11687/
GI-DocGen vulnerable to Reflected XSS via unescaped query strings | GitLab Advisory Database (GLAD)
CVE-2025-11687 GI-DocGen vulnerable to Reflected XSS via unescaped query strings: A flaw was found in GI-DocGen. This vulnerability allows arbitrary JavaScript...
https://quickbooks.intuit.com/learn-support/en-uk/do-more-with-quickbooks/unescaped-character-in-the-xml-error/00/1164563
Unescaped character & in the XML error
in thecharacterxmlerror
https://advisories.gitlab.com/composer/froxlor/froxlor/CVE-2026-41229/
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation...
CVE-2026-41229 Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API): PhpHelper::parseArrayToString()...
https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99142
Unescaped " escape with backslash issue | DevCentral
escapebackslashissuedevcentral
https://advisories.gitlab.com/pypi/pretalx/CVE-2026-41426/
pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders |...
CVE-2026-41426 pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders: An unauthenticated attacker can send arbitrary...
mail templates
https://advisories.gitlab.com/golang/github.com/traefik/traefik/v3/CVE-2026-29777/
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values |...
CVE-2026-29777 Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values: There is a potential vulnerability in Traefik's...
https://advisories.gitlab.com/npm/openclaw/CVE-2026-22178/
OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction...
CVE-2026-22178 OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction: extensions/feishu/src/bot.ts constructed...
https://advisories.gitlab.com/pypi/ha-mcp/CVE-2026-32112/
ha-mcp has XSS via Unescaped HTML in OAuth Consent Form | GitLab Advisory Database (GLAD)
CVE-2026-32112 ha-mcp has XSS via Unescaped HTML in OAuth Consent Form: The ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings...
https://bugzilla.mozilla.org/show_bug.cgi?id=57548
57548 - [regression] filenames dragged into moz are unescaped (dnd spaces)
RESOLVED (alecf) in SeaMonkey - UI Design. Last updated 2004-11-23.
regressionfilenamesdraggedmozdnd
https://advisories.gitlab.com/golang/github.com/traefik/traefik/CVE-2026-29777/
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values |...
CVE-2026-29777 Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values: There is a potential vulnerability in Traefik's...
https://advisories.gitlab.com/golang/github.com/traefik/traefik/v2/CVE-2026-29777/
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values |...
CVE-2026-29777 Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values: There is a potential vulnerability in Traefik's...
https://wordpress.org/support/topic/bug-fix-for-unescaped-title-attributes-in-admin-ui/
Bug Fix for Unescaped Title Attributes in Admin UI | WordPress.org
Aug 22, 2016 - Bug Fix for Unescaped Title Attributes in Admin UI Resolved pwenzel (@pwenzel) 11 years, 5 months ago My client has entered HTML tags in the title field of...
bug fixtitle attributesadmin ui
https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99131
Unescaped " escape with backslash issue | DevCentral
escapebackslashissuedevcentral
https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99138
Unescaped " escape with backslash issue | DevCentral
escapebackslashissuedevcentral
https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99143
Unescaped " escape with backslash issue | DevCentral
escapebackslashissuedevcentral
https://bugzilla.mozilla.org/show_bug.cgi?id=1155131
1155131 - [Tests] Discourage unescaped innerHTML through test failures
RESOLVED (fbraun) in Firefox OS Graveyard - Gaia. Last updated 2018-02-28.
testsdiscourageinnerhtmlfailures
https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99147
Unescaped " escape with backslash issue | DevCentral
escapebackslashissuedevcentral
https://lists.w3.org/Archives/Public/public-html-bugzilla/2009Mar/0005.html
[Bug 6670] New: Allow unescaped &s, at least in attributes that accept URLs from...
https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99149
Unescaped " escape with backslash issue | DevCentral
escapebackslashissuedevcentral