boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-791

Weakness type CWE-791 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
10100

Monthly trend

▃▅▁█▅▃

2026-05 1 · 2026-06 2 · 2026-07 0 · 2026-08 4 · 2026-09 2 · 2026-10 1

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-862066.965.0—Access control filter bypass allows unauthorised access to APIs
CVE-2026-119987.640.8—AngularJS XSS via SCE resource URL sanitization bypass
CVE-2026-199292.140.4—OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elem…
CVE-2026-482086.539.7—Denial-of-Service via SVG Rendering in Ticket
CVE-2026-759792.133.4—xianrendzw EasyReport SQL Preview Endpoint DesignerController.java previewSqlText speci…
CVE-2026-781402.033.1—Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special …
CVE-2026-94982.131.1—Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used …
CVE-2026-186322.131.1—langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a…
CVE-2026-1027712.013.6—Naichen ThinkCMF Email Template MailController.php templatePut special elements in temp…
CVE-2026-1035402.113.4—formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab spec…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
dromara2
formtools.org1
google1
langgenius1
n-able1
naichen1
otrs1
xianrendzw1