boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1275

Weakness type CWE-1275 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
15150

Monthly trend

█▁▂▂

2026-05 13 · 2026-06 0 · 2026-07 1 · 2026-08 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-556884.012.7AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeC…
CVE-2026-738476.86.4Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database comp…
CVE-2026-84092.34.0Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84102.34.0Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84112.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84122.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84132.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84142.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84152.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84162.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84272.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84322.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84332.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84342.33.1Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…
CVE-2026-84352.31.8Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concr…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
concrete cms13
asynchttpclient1
emlog1