Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1336
Weakness type CWE-1336 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 106 | 104 | 3 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▃█▅▂
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 2 · 2026-05 8 · 2026-06 7 · 2026-07 14 · 2026-08 45 · 2026-09 23 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-4040 | 9.8 | 99.9 | KEV | Unauthenticated arbitrary file read and remote code execution in CrushFTP |
| CVE-2024-23692 | 9.8 | 99.9 | KEV | Rejetto HTTP File Server 2.3m Unauthenticated RCE |
| CVE-2026-75650 | 10.0 | 90.1 | KEV | Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine … |
| CVE-2026-28496 | 9.4 | 79.0 | — | FOSSBilling: Server-side template injection in Twig template rendering enables informat… |
| CVE-2026-73299 | 10.0 | 77.5 | — | Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core N… |
| CVE-2026-12370 | 7.6 | 73.6 | — | Remote Code Execution Vulnerability |
| CVE-2026-48323 | 10.0 | 70.9 | — | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Te… |
| CVE-2026-22244 | 8.5 | 69.5 | — | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that l… |
| CVE-2026-52889 | 9.8 | 68.9 | — | Formie: Server-Side Template Injection in Formie Hidden field defaults |
| CVE-2026-40478 | 9.0 | 67.2 | — | Improper neutralization of specific syntax patterns for unauthorized expressions in Thy… |
| CVE-2026-88064 | 8.8 | 65.9 | — | Backstage: Improper input validation in TechDocs MkDocs configuration |
| CVE-2026-54718 | 7.2 | 63.0 | — | Silverstripe Advanced Workflow: Remote code execution via advanced workflow email template |
| CVE-2026-65974 | 9.9 | 62.4 | — | ERPNext: Server-Side Template Injection leading to Remote Code Execution |
| CVE-2026-77136 | 9.5 | 60.5 | — | Server-Side Template Injection in extension "powermail" (powermail) |
| CVE-2026-40477 | 9.0 | 59.7 | — | Improper restriction of the scope of accessible objects in Thymeleaf expressions |
| CVE-2026-90970 | 9.9 | 59.7 | — | Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway |
| CVE-2026-34906 | 9.3 | 57.9 | — | Server-Side Template Injection (SSTI) in Wirtualna Uczelnia |
| CVE-2026-66613 | 9.8 | 57.1 | — | WordPress JetEngine plugin <= 3.8.14 - Remote Code Execution (RCE) vulnerability |
| CVE-2026-89094 | 9.9 | 56.7 | — | — |
| CVE-2026-72827 | 8.7 | 56.7 | — | Grav CMS before 2.0.13 Remote Code Execution via Twig |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| orval-labs | 7 |
| acacode | 4 |
| frappe | 3 |
| getgrav | 3 |
| koxudaxi | 3 |
| adobe | 2 |
| craftcms | 2 |
| dromara | 2 |
| nozomi networks | 2 |
| oscal-compass | 2 |
| rejetto | 2 |
| thymeleaf | 2 |
| typo3 | 2 |
| verbb | 2 |
| adfinis | 1 |