CWE-84: Improper Neutralization of Encoded URI Schemes in a Web Page

low-risk

The web application improperly neutralizes user-controlled input for executable script disguised with URI encodings.

Abstraction: Variant

Common Consequences

Integrity Unexpected State

Real-World Examples (10)

CVE CVSS EPSS KEV
CVE-2023-25571 6.8 0.7%
CVE-2022-40181 8.3 0.7%
CVE-2024-45045 6.3 0.5%
CVE-2020-7011 6.1 0.3%
CVE-2021-3824 6.1 0.3%
CVE-2025-30203 4.8 0.2%
CVE-2023-30959 4.1 0.2%
CVE-2025-25329 5.5 0.1%
CVE-2024-42184 2.5 0.1%
CVE-2025-25324 5.5 0.1%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal