Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-180
Weakness type CWE-180 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 26 | 26 | 0 |
Monthly trend
▂▂▃▄▆█▂
2026-04 1 · 2026-05 1 · 2026-06 3 · 2026-07 4 · 2026-08 7 · 2026-09 9 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-39364 | 8.2 | 74.0 | — | Vite has a `server.fs.deny` bypass with queries |
| CVE-2026-73420 | 9.1 | 52.5 | — | NextAuth.js: Email normalizer validates the address before Unicode normalization, allow… |
| CVE-2026-82481 | 8.7 | 51.4 | — | — |
| CVE-2026-73416 | 6.1 | 50.0 | — | jupyterlab: PyPI extension blocklist package-name canonicalization bypass |
| CVE-2026-15704 | 9.8 | 49.5 | — | CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse Ba… |
| CVE-2026-100230 | 5.3 | 49.5 | — | — |
| CVE-2026-49984 | 7.7 | 45.1 | — | Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrar… |
| CVE-2026-90813 | 2.1 | 44.3 | — | cosmicstack-labs mercury-agent Shell Command Execution permissions.ts checkShellCommand… |
| CVE-2026-105050 | 7.1 | 41.8 | — | — |
| CVE-2026-52747 | 8.6 | 38.9 | — | ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-… |
| CVE-2026-62999 | 7.5 | 36.1 | — | Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (… |
| CVE-2026-95811 | 6.5 | 32.4 | — | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, f… |
| CVE-2026-76203 | 5.1 | 31.6 | — | CSS sanitizer bypass in Pentestify report themes allows forced outbound requests |
| CVE-2026-69246 | 7.2 | 28.6 | — | Guzzle: Noncanonical host can bypass host-based checks |
| CVE-2026-7120 | 5.3 | 28.5 | — | @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths |
| CVE-2026-72917 | 5.9 | 26.0 | — | AnythingLLM: Password recovery accepts one recovery code twice after whitespace normali… |
| CVE-2026-79300 | 3.5 | 15.8 | — | — |
| CVE-2026-42462 | 7.0 | 14.7 | — | Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring |
| CVE-2026-100674 | 5.3 | 13.0 | — | stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization |
| CVE-2026-97764 | 3.7 | 12.2 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| guzzle | 2 |
| @auth | 1 |
| @fastify/static | 1 |
| allauth | 1 |
| ash-project | 1 |
| copier-org | 1 |
| cosmicstack-labs | 1 |
| eclipse foundation | 1 |
| fedify-dev | 1 |
| go-git | 1 |
| input-leap | 1 |
| jpadilla | 1 |
| jupyterlab | 1 |
| kestra-io | 1 |
| maalfer | 1 |