Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-116
Weakness type CWE-116 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 138 | 134 | 4 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▁▂▇▅██▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 3 · 2026-03 3 · 2026-04 0 · 2026-05 5 · 2026-06 30 · 2026-07 22 · 2026-08 36 · 2026-09 34 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-38475 | 9.1 | 100.0 | KEV | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches f… |
| CVE-2022-24682 | 6.1 | 98.2 | KEV | Synacor Zimbra Collaborate Suite (ZCS) |
| CVE-2026-20245 | 7.8 | 97.9 | KEV | Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability |
| CVE-2022-42948 | 9.8 | 85.5 | KEV | Fortra Cobalt Strike |
| CVE-2026-56379 | 9.2 | 75.6 | — | ImageMagick - Command Injection via SVG Decoder |
| CVE-2026-48358 | 9.1 | 67.3 | — | Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116) |
| CVE-2026-49844 | 6.3 | 55.5 | — | Apache Log4j API: Improper serialization of non-finite floating-point values in MapMess… |
| CVE-2026-25755 | 8.8 | 55.1 | — | jsPDF has PDF Object Injection via Unsanitized Input in addJS Method |
| CVE-2026-94545 | 5.3 | 54.9 | — | Satori-generated SVG has improper escaping |
| CVE-2026-62184 | 8.7 | 54.5 | — | luci-app-banip Log Monitor IP Extraction Bypass |
| CVE-2026-54182 | 8.1 | 54.4 | — | backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled H… |
| CVE-2026-73417 | 8.6 | 53.3 | — | JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) |
| CVE-2026-54699 | 7.7 | 53.0 | — | Warp: OS command injection when opening terminal links from WSL |
| CVE-2026-50659 | 6.5 | 52.9 | — | .NET Spoofing Vulnerability |
| CVE-2026-12044 | 8.7 | 51.9 | — | pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog t… |
| CVE-2026-82756 | 6.3 | 50.7 | — | ash_authentication_oauth2_server interpolates a tenant-derived value into the WWW-Authe… |
| CVE-2026-48376 | 5.4 | 50.7 | — | ColdFusion | Improper Encoding or Escaping of Output (CWE-116) |
| CVE-2026-90999 | 9.8 | 50.3 | — | Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileg… |
| CVE-2026-62681 | 9.3 | 49.5 | — | Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) |
| CVE-2026-62682 | 9.3 | 49.5 | — | Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrl… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| orval-labs | 7 |
| apache | 6 |
| misp | 6 |
| duck-organization | 5 |
| parallax | 4 |
| pgadmin.org | 3 |
| adobe | 2 |
| angular | 2 |
| ash-project | 2 |
| dell | 2 |
| ericcornelissen | 2 |
| glpi-project | 2 |
| 2 | |
| honojs | 2 |
| loytec | 2 |