CWE-149: Improper Neutralization of Quoting Syntax

low-risk

Quotes injected into a product can be used to compromise a system. As data are parsed, an injected/absent/duplicate/malformed use of quotes may cause the process to take unexpected actions.

Abstraction: Variant

Common Consequences

Integrity Unexpected State

Real-World Examples (4)

CVE CVSS EPSS KEV
CVE-2025-1094 8.1 83.1%
CVE-2023-36479 3.5 1.4%
CVE-2025-43878 6.0 0.1%
CVE-2018-25135 9.8 0.1%
9
/ 100
low-risk
Active Threat 9/50 · Minimal
Exploit Availability 0/50 · Minimal