inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","DatePublished":"2026-04-22T07:00:00.000Z","DomainCount":446},{"CVEId":"CVE-2026-3108","Title":"Terminal Escape Injection in mmctl Report Posts Command","Description":"Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences that enable screen manipulation, fake prompts, and clipboard hijacking.. Mattermost Advisory ID: MMSA-2026-00599","DatePublished":"2026-03-26T07:00:00.000Z","DomainCount":78},{"CVEId":"CVE-2025-65082","Title":"Apache HTTP Server: CGI environment variable override","Description":"Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.\n\nThis issue affects Apache HTTP Server from 2.4.0 through 2.4.65.\n\nUsers are recommended to upgrade to version 2.4.66 which fixes the issue.","DatePublished":"2025-12-05T08:00:00.000Z","DomainCount":1297929},{"CVEId":"CVE-2025-55754","Title":"Apache Tomcat: console manipulation via escape sequences in log messages","Description":"Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.\n\nTomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected.\nUsers are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.","DatePublished":"2025-10-27T07:00:00.000Z","DomainCount":2303},{"CVEId":"CVE-2025-55193","Title":"Active Record logging vulnerable to ANSI escape injection","Description":"Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.","DatePublished":"2025-08-13T07:00:00.000Z","DomainCount":1},{"CVEId":"CVE-2024-47252","Title":"Apache HTTP Server: mod_ssl error log variable escaping","Description":"Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations.\n\nIn a logging configuration where CustomLog is used with \"%{varname}x\" or \"%{varname}c\" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.","DatePublished":"2025-07-10T07:00:00.000Z","DomainCount":1248307}],"DistributionByPopularity":{"Top10KUsage":133,"Top100KUsage":2164,"Top1MUsage":26733,"Top10MUsage":202179,"TotalCount":1300448,"TotalDomainCount":57867524},"TLDs":[{"TLD":"com","DomainCount":471807},{"TLD":"de","DomainCount":88213},{"TLD":"org","DomainCount":63614},{"TLD":"net","DomainCount":52643},{"TLD":"nl","DomainCount":40191},{"TLD":"ru","DomainCount":39959},{"TLD":"it","DomainCount":39068},{"TLD":"cz","DomainCount":33092},{"TLD":"fr","DomainCount":26408},{"TLD":"pl","DomainCount":24160}],"DomainCount":1300448,"success_msg":[],"error_msg":[],"error":[]}}}

CWE-150


Improper Neutralization of Escape, Meta, or Control Sequences

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.


We have discovered 1,300,448 live websites that are affected by CWE-150.

Contact us to get more info









CVEs

  • Count - 6



Website Distribution by Country

Number of websites using CWE-150
United States383,929 websites



Germany154,364 websites
France80,692 websites
Japan58,016 websites
Netherlands53,523 websites
Russia45,343 websites
Italy44,100 websites
Czech Republic39,990 websites
GB32,941 websites
Singapore31,604 websites

Website Distribution by TLD

Number of websites using CWE-150
.com471,807 websites
.de88,213 websites
.org63,614 websites
.net52,643 websites
.nl40,191 websites
.ru39,959 websites
.it39,068 websites
.cz33,092 websites
.fr26,408 websites
.pl24,160 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-150
DiscoveredCVEDescriptionWebsites
Apr, 2026CVE-2026-6019 BaseCookie.js_output() does not neutralize embedded characters446
Mar, 2026CVE-2026-3108 Terminal Escape Injection in mmctl Report Posts Command78
Dec, 2025CVE-2025-65082 Apache HTTP Server: CGI environment variable override1,297,929
Oct, 2025CVE-2025-55754 Apache Tomcat: console manipulation via escape sequences in log messages2,303
Aug, 2025CVE-2025-55193 Active Record logging vulnerable to ANSI escape injection1
Jul, 2025CVE-2024-47252 Apache HTTP Server: mod_ssl error log variable escaping1,248,307
List of the most common CVEs that are part of CWE-150
DiscoveredCVEDescriptionWebsites
Dec, 2025CVE-2025-65082 Apache HTTP Server: CGI environment variable override1,297,929
Jul, 2025CVE-2024-47252 Apache HTTP Server: mod_ssl error log variable escaping1,248,307
Oct, 2025CVE-2025-55754 Apache Tomcat: console manipulation via escape sequences in log messages2,303
Apr, 2026CVE-2026-6019 BaseCookie.js_output() does not neutralize embedded characters446
Mar, 2026CVE-2026-3108 Terminal Escape Injection in mmctl Report Posts Command78
Aug, 2025CVE-2025-55193 Active Record logging vulnerable to ANSI escape injection1

Websites affected by CWE-150

Top websites that are affected by CWE-150. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.***.****.****.************.net United States***
*********.net United States***
****************.net United States*,***
*****.cz Czech Republic*,***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******.net Sweden*,***
******************.com United States*,***
*******.**.com United States*,***
See full domain list