Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1275
Weakness type CWE-1275 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 22 | 22 | 0 |
Monthly trend
█▁▂▃▃▂
2026-05 13 · 2026-06 0 · 2026-07 1 · 2026-08 3 · 2026-09 3 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-69215 | 6.8 | 41.2 | — | Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin |
| CVE-2026-47889 | 7.5 | 35.0 | — | Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse |
| CVE-2026-53660 | 7.4 | 33.1 | — | OpenAM Insecure SSO Cookie Initialization |
| CVE-2026-55688 | 4.0 | 24.1 | — | AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeC… |
| CVE-2026-73847 | 6.8 | 11.2 | — | Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database comp… |
| CVE-2026-8409 | 2.3 | 10.8 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8410 | 2.3 | 10.8 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8411 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8412 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8413 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8414 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8415 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8416 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8427 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8432 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8433 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-8434 | 2.3 | 8.5 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
| CVE-2026-81888 | 5.4 | 8.1 | — | @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CS… |
| CVE-2026-61687 | 7.1 | 5.9 | — | hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in Va… |
| CVE-2026-8435 | 2.3 | 5.4 | — | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| concrete cms | 13 |
| asynchttpclient | 3 |
| emlog | 1 |
| hatchet-dev | 1 |
| honojs | 1 |
| http4s | 1 |
| openidentityplatform | 1 |
| spring | 1 |