boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-1336

Weakness type CWE-1336 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1061043

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▃█▅▂

2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 8 · 2026-06 7 · 2026-07 14 · 2026-08 45 · 2026-09 23 · 2026-10 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-40409.899.9KEVUnauthenticated arbitrary file read and remote code execution in CrushFTP
CVE-2024-236929.899.9KEVRejetto HTTP File Server 2.3m Unauthenticated RCE
CVE-2026-7565010.090.1KEVAdobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine …
CVE-2026-284969.479.0—FOSSBilling: Server-side template injection in Twig template rendering enables informat…
CVE-2026-7329910.077.5—Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core N…
CVE-2026-123707.673.6—Remote Code Execution Vulnerability
CVE-2026-4832310.070.9—Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Te…
CVE-2026-222448.569.5—OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that l…
CVE-2026-528899.868.9—Formie: Server-Side Template Injection in Formie Hidden field defaults
CVE-2026-404789.067.2—Improper neutralization of specific syntax patterns for unauthorized expressions in Thy…
CVE-2026-880648.865.9—Backstage: Improper input validation in TechDocs MkDocs configuration
CVE-2026-547187.263.0—Silverstripe Advanced Workflow: Remote code execution via advanced workflow email template
CVE-2026-659749.962.4—ERPNext: Server-Side Template Injection leading to Remote Code Execution
CVE-2026-771369.560.5—Server-Side Template Injection in extension "powermail" (powermail)
CVE-2026-404779.059.7—Improper restriction of the scope of accessible objects in Thymeleaf expressions
CVE-2026-909709.959.7—Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway
CVE-2026-349069.357.9—Server-Side Template Injection (SSTI) in Wirtualna Uczelnia
CVE-2026-666139.857.1—WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability
CVE-2026-890949.956.7——
CVE-2026-728278.756.7—Grav CMS before 2.0.13 Remote Code Execution via Twig

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
orval-labs7
acacode4
frappe3
getgrav3
koxudaxi3
adobe2
craftcms2
dromara2
nozomi networks2
oscal-compass2
rejetto2
thymeleaf2
typo32
verbb2
adfinis1