Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-93'

View all threats tagged with 'cwe-93'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-93

Threats Tagged 'cwe-93'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-0673: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') in bdthemes Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor AddonsCVE-2026-0673
0

The Element Pack Addons for Elementor WordPress plugin is vulnerable to Email Header Injection in all versions up to and including 8.3.15. The vulnerability arises from insufficient sanitization of newline characters in user input processed by the `element_pack_contact_form` AJAX action, allowing unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form.

Join the discussion
CVE-2026-0673: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') in bdthemes Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor AddonsCVE-2026-0673
0

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers. This makes it possible for unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form.

Join the discussion
CVE-2026-65636: CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') in ufirstgroup ymlrCVE-2026-65636
0

Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inject arbitrary content into generated YAML documents through document comments. Ymlr.document!/2 interpolates each caller-supplied comment string into the output behind a single # prefix without validating it or escaping line breaks. Because a YAML comment is terminated by a line break, the first carriage return or line feed in the comment string ends the comment context and everything after it is emitted at column 0 of the document body. An attacker who controls text that the host application passes as a comment can forge top-level mapping keys, override values the application itself set, and emit --- or ... markers that split the output into additional documents. Downstream consumers of the generated YAML, such as configuration loaders, deployment manifests, CI pipelines and data importers, parse the injected content as legitimate data. The same clause backs Ymlr.document/2, Ymlr.documents!/2 and Ymlr.documents/2, so every document encoding entry point is affected. This vulnerability is associated with program files lib/ymlr.ex and program routines 'Elixir.Ymlr':document!/2, 'Elixir.Ymlr':documents!/2. This issue affects ymlr from 0.0.1 before 5.1.6.

Join the discussion
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches… (CVE-2026-44092)CVE-2026-44092
0

CVE-2026-44092 is a vulnerability in Phoenix Contact CHARX SEC-3150 devices where an unauthenticated remote attacker can inject malicious input into the ModbusServer application due to lack of input validation. This allows network-adjacent attackers to bypass firewall rules without requiring authentication. The vulnerability has been assigned a high severity rating by ZDI with a CVSS 4.0 vector indicating network attack vector and no user interaction required. No patch or remediation information is currently available.

Join the discussion
ZDI-26-447: Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution VulnerabilityCVE-2026-12357
0

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-12357.

Join the discussion
CVE-2026-15429: CWE-93 Improper neutralization of CRLF sequences ('CRLF injection') in TP-Link Systems Inc. Archer VX1800v v1CVE-2026-15429
0

A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data.  An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges.

Join the discussion
CVE-2026-50188: CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') in getkirby kirbyCVE-2026-50188
0

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could allow newline characters in a header value to inject a separate unintended request header to the remote service. This issue is fixed in versions 4.9.4 and 5.4.4.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cwe-93
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses