Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-602
Weakness type CWE-602 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 72 | 70 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁█▄▃▃▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 35 · 2026-07 15 · 2026-08 10 · 2026-09 9 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2023-42787 | 6.5 | 71.0 | — | — |
| CVE-2026-72867 | 9.9 | 60.0 | — | Dokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fie… |
| CVE-2026-42266 | 8.8 | 56.8 | — | JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (mali… |
| CVE-2026-54104 | 8.7 | 52.4 | — | U.S. GAO EPDS and CBCA EDS client-based privilege escalation |
| CVE-2026-45274 | 6.9 | 51.8 | — | MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enf… |
| CVE-2026-73267 | 7.7 | 48.2 | — | Clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.nam… |
| CVE-2025-4527 | 2.9 | 46.5 | — | Dígitro NGC Explorer Password Transmission client-side enforcement of server-side security |
| CVE-2026-63301 | 7.0 | 45.5 | — | Denial of Service in Quick.CMS |
| CVE-2026-67363 | 7.7 | 44.4 | — | Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2… |
| CVE-2026-89175 | 6.9 | 43.5 | — | Kingdom Communication Associated|Smart Video Intercom System - Client-Side Authentication |
| CVE-2026-84841 | 5.5 | 43.4 | — | tsi-coop tsi-dpdp-cms client-side enforcement of server-side security |
| CVE-2026-64813 | 10.0 | 42.3 | — | — |
| CVE-2026-65051 | 6.9 | 40.0 | — | Ninja Forms Server-Side Validation Bypass via Client-Controlled Field Metadata Merge in… |
| CVE-2026-84110 | 5.5 | 39.8 | — | Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-s… |
| CVE-2026-77026 | 6.9 | 37.2 | — | Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms ext… |
| CVE-2026-77999 | 8.7 | 34.8 | — | Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to … |
| CVE-2026-82189 | 8.7 | 34.8 | — | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store… |
| CVE-2026-59504 | 9.1 | 34.7 | — | Priority – CWE-602: Client-Side Enforcement of Server-Side Security |
| CVE-2026-73627 | 6.0 | 34.3 | — | JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass |
| CVE-2026-46485 | 8.2 | 34.1 | — | Dash: Users can write to config despire permissions (OIDC tested) |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| 38 | |
| ibm | 2 |
| j2commerce.com | 2 |
| johnson & johnson | 2 |
| jupyterlab | 2 |
| balbooa.com | 1 |
| capgo | 1 |
| civilian board of contract appeals | 1 |
| dfir-iris | 1 |
| dokploy | 1 |
| dígitro | 1 |
| fortinet | 1 |
| gobito informatics technologies engineering industry and trade ltd. co | 1 |
| government accountability office | 1 |
| jetbrains | 1 |