Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-472
Weakness type CWE-472 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 66 | 65 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▄█▄▃▃▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 11 · 2026-06 28 · 2026-07 10 · 2026-08 6 · 2026-09 8 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-35939 | 6.9 | 70.5 | KEV | Craft CMS stores user-provided content in session files |
| CVE-2026-65052 | 8.7 | 45.8 | — | Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in Lis… |
| CVE-2026-67363 | 7.7 | 44.4 | — | Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2… |
| CVE-2026-77999 | 8.7 | 34.8 | — | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to … |
| CVE-2026-82189 | 8.7 | 34.8 | — | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store… |
| CVE-2026-14430 | 8.8 | 33.3 | — | — |
| CVE-2026-59817 | 5.3 | 32.2 | — | Ghost: Paid gift memberships obtainable at minimal cost via the donations feature |
| CVE-2026-56877 | 6.3 | 31.2 | — | — |
| CVE-2026-13841 | 8.3 | 30.5 | — | — |
| CVE-2026-9968 | 8.8 | 30.0 | — | — |
| CVE-2026-10524 | 7.5 | 29.8 | — | CoCart < 4.9.0 - Unauthenticated Arbitrary Price Manipulation |
| CVE-2026-94374 | 8.3 | 28.8 | — | MISP: IDOR via Client-Supplied Report ID in Module Results Processing Allows Reparentin… |
| CVE-2025-59382 | 1.2 | 28.5 | — | QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) |
| CVE-2026-16620 | 7.5 | 28.1 | — | WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Se… |
| CVE-2026-10963 | 8.8 | 27.6 | — | — |
| CVE-2026-10964 | 8.8 | 27.6 | — | — |
| CVE-2026-10965 | 8.8 | 27.6 | — | — |
| CVE-2026-10987 | 8.8 | 27.6 | — | — |
| CVE-2026-84762 | 5.3 | 25.9 | — | WordPress WP EasyPay plugin <= 4.5.3 - Bypass Vulnerability vulnerability |
| CVE-2026-13938 | 8.8 | 25.7 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 41 | |
| j2commerce.com | 2 |
| abis technology ltd. co | 1 |
| balbooa.com | 1 |
| craft | 1 |
| jenkins project | 1 |
| misp | 1 |
| mohammadr3z | 1 |
| qnap systems | 1 |
| red hat | 1 |
| saad iqbal | 1 |
| saturday drive | 1 |
| skillable | 1 |
| tryghost | 1 |
| wpmanageninja | 1 |