Robuta

https://pear.php.net/bugs/bug.php?id=10324 Bug #10324 :: Unescaped values on invalid bugs bugvaluesinvalid https://advisories.gitlab.com/golang/istio.io/istio/CVE-2026-39350/ Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots | GitLab Advisory... CVE-2026-39350 Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots: The serviceAccounts and notServiceAccounts fields in... istioregexinjectionviadots https://advisories.gitlab.com/composer/froxlor/froxlor/GHSA-gc9w-cc93-rjv8/ Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation... GHSA-gc9w-cc93-rjv8 Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API):... https://advisories.gitlab.com/gem/govuk_tech_docs/CVE-2024-22048/ govuk_tech_docs vulnerable to unescaped HTML on search results page | GitLab Advisory Database... CVE-2024-22048 govuk_tech_docs vulnerable to unescaped HTML on search results page: Pages that are indexed in search results have their entire contents... https://advisories.gitlab.com/composer/thorsten/phpmyfaq/GHSA-pm8c-3qq3-72w7/ phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields |... GHSA-pm8c-3qq3-72w7 phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields: CurrentUser::setTokenData() in... sql injection https://packagist.org/packages/luzrain/doctrine-json-unescaped-type luzrain/doctrine-json-unescaped-type - Packagist.org Preventing json Doctrine type to escape unicode characters. doctrinejsontypepackagist https://advisories.gitlab.com/golang/miniflux.app/v2/CVE-2023-27592/ Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler |... CVE-2023-27592 Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler: Since v2.0.25, Miniflux will automatically... https://advisories.gitlab.com/nuget/log4net/CVE-2026-40021/ Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML... CVE-2026-40021 Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters: Apache Log4net's... https://advisories.gitlab.com/maven/org.apache.logging.log4j/log4j-1.2-api/CVE-2026-34479/ Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0... CVE-2026-34479 Apache Log4j 1 to Log4j 2 bridge: silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters: The Log4j1XmlLayout... https://lists.w3.org/Archives/Public/public-html-bugzilla/2010Apr/0425.html [Bug 6670] Allow unescaped &s, at least in attributes that accept URLs from bugzilla@jessica.w3.org... https://advisories.gitlab.com/golang/github.com/beego/beego/CVE-2025-30223/ Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input |... CVE-2025-30223 Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input: A Cross-Site Scripting (XSS) vulnerability... https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99136 Unescaped " escape with backslash issue | DevCentral escapebackslashissuedevcentral https://advisories.gitlab.com/gem/prosemirror_to_html/CVE-2025-64501/ Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values | GitLab Advisory... CVE-2025-64501 Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values: The prosemirror_to_html gem is vulnerable to Cross-Site... cross site scripting https://advisories.gitlab.com/pypi/wger/CVE-2026-40353/ wger has Stored XSS via Unescaped License Attribution Fields | GitLab Advisory Database (GLAD) CVE-2026-40353 wger has Stored XSS via Unescaped License Attribution Fields: The AbstractLicenseModel.attribution_link property in wger/utils/models.py... https://spring.io/security/cve-2026-22744/ CVE-2026-22744: RediSearch Query via Unescaped TAG Filter Values in RedisVectorStore Level up your Java code and explore what Spring can do for you. https://advisories.gitlab.com/composer/wwbn/avideo/GHSA-gmpc-fxg2-vcmq/ AVideo has Stored XSS via Unescaped Menu Item Fields in TopMenu Plugin | GitLab Advisory Database... GHSA-gmpc-fxg2-vcmq AVideo has Stored XSS via Unescaped Menu Item Fields in TopMenu Plugin: The TopMenu plugin renders menu item fields (icon classes, URLs,... https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99134 Unescaped " escape with backslash issue | DevCentral escapebackslashissuedevcentral https://advisories.gitlab.com/maven/net.sourceforge.pmd/pmd-core/CVE-2026-28338/ PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages |... CVE-2026-28338 PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages: PMD's vbhtml and yahtml report formats insert... https://advisories.gitlab.com/pypi/praisonaiagents/CVE-2026-34937/ PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution | GitLab Advisory... CVE-2026-34937 PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution: run_python() in praisonai constructs a shell command string by... shellinjectionrun https://advisories.gitlab.com/pypi/gi-docgen/CVE-2025-11687/ GI-DocGen vulnerable to Reflected XSS via unescaped query strings | GitLab Advisory Database (GLAD) CVE-2025-11687 GI-DocGen vulnerable to Reflected XSS via unescaped query strings: A flaw was found in GI-DocGen. This vulnerability allows arbitrary JavaScript... https://quickbooks.intuit.com/learn-support/en-uk/do-more-with-quickbooks/unescaped-character-in-the-xml-error/00/1164563 Unescaped character & in the XML error in thecharacterxmlerror https://advisories.gitlab.com/composer/froxlor/froxlor/CVE-2026-41229/ Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation... CVE-2026-41229 Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API): PhpHelper::parseArrayToString()... https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99142 Unescaped " escape with backslash issue | DevCentral escapebackslashissuedevcentral https://advisories.gitlab.com/pypi/pretalx/CVE-2026-41426/ pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders |... CVE-2026-41426 pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders: An unauthenticated attacker can send arbitrary... mail templates https://advisories.gitlab.com/golang/github.com/traefik/traefik/v3/CVE-2026-29777/ Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values |... CVE-2026-29777 Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values: There is a potential vulnerability in Traefik's... https://advisories.gitlab.com/npm/openclaw/CVE-2026-22178/ OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction... CVE-2026-22178 OpenClaw has ReDoS and regex injection via unescaped Feishu mention metadata in RegExp construction: extensions/feishu/src/bot.ts constructed... https://advisories.gitlab.com/pypi/ha-mcp/CVE-2026-32112/ ha-mcp has XSS via Unescaped HTML in OAuth Consent Form | GitLab Advisory Database (GLAD) CVE-2026-32112 ha-mcp has XSS via Unescaped HTML in OAuth Consent Form: The ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings... https://bugzilla.mozilla.org/show_bug.cgi?id=57548 57548 - [regression] filenames dragged into moz are unescaped (dnd spaces) RESOLVED (alecf) in SeaMonkey - UI Design. Last updated 2004-11-23. regressionfilenamesdraggedmozdnd https://advisories.gitlab.com/golang/github.com/traefik/traefik/CVE-2026-29777/ Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values |... CVE-2026-29777 Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values: There is a potential vulnerability in Traefik's... https://advisories.gitlab.com/golang/github.com/traefik/traefik/v2/CVE-2026-29777/ Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values |... CVE-2026-29777 Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values: There is a potential vulnerability in Traefik's... https://wordpress.org/support/topic/bug-fix-for-unescaped-title-attributes-in-admin-ui/ Bug Fix for Unescaped Title Attributes in Admin UI | WordPress.org Aug 22, 2016 - Bug Fix for Unescaped Title Attributes in Admin UI Resolved pwenzel (@pwenzel) 11 years, 5 months ago My client has entered HTML tags in the title field of... bug fixtitle attributesadmin ui https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99131 Unescaped " escape with backslash issue | DevCentral escapebackslashissuedevcentral https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99138 Unescaped " escape with backslash issue | DevCentral escapebackslashissuedevcentral https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99143 Unescaped " escape with backslash issue | DevCentral escapebackslashissuedevcentral https://bugzilla.mozilla.org/show_bug.cgi?id=1155131 1155131 - [Tests] Discourage unescaped innerHTML through test failures RESOLVED (fbraun) in Firefox OS Graveyard - Gaia. Last updated 2018-02-28. testsdiscourageinnerhtmlfailures https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99147 Unescaped " escape with backslash issue | DevCentral escapebackslashissuedevcentral https://lists.w3.org/Archives/Public/public-html-bugzilla/2009Mar/0005.html [Bug 6670] New: Allow unescaped &s, at least in attributes that accept URLs from... https://community.f5.com/discussions/technicalforum/unescaped--escape-with-backslash-issue/99130/replies/99149 Unescaped " escape with backslash issue | DevCentral escapebackslashissuedevcentral