Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-791
Weakness type CWE-791 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 10 | 10 | 0 |
Monthly trend
▃▅▁█▅▃
2026-05 1 · 2026-06 2 · 2026-07 0 · 2026-08 4 · 2026-09 2 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-86206 | 6.9 | 65.0 | — | Access control filter bypass allows unauthorised access to APIs |
| CVE-2026-11998 | 7.6 | 40.8 | — | AngularJS XSS via SCE resource URL sanitization bypass |
| CVE-2026-19929 | 2.1 | 40.4 | — | OpenBoxes Template Processing DocumentController.groovy buildZebraTemplate special elem… |
| CVE-2026-48208 | 6.5 | 39.7 | — | Denial-of-Service via SVG Rendering in Ticket |
| CVE-2026-75979 | 2.1 | 33.4 | — | xianrendzw EasyReport SQL Preview Endpoint DesignerController.java previewSqlText speci… |
| CVE-2026-78140 | 2.0 | 33.1 | — | Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special … |
| CVE-2026-9498 | 2.1 | 31.1 | — | Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used … |
| CVE-2026-18632 | 2.1 | 31.1 | — | langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a… |
| CVE-2026-102771 | 2.0 | 13.6 | — | Naichen ThinkCMF Email Template MailController.php templatePut special elements in temp… |
| CVE-2026-103540 | 2.1 | 13.4 | — | formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab spec… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dromara | 2 |
| formtools.org | 1 |
| 1 | |
| langgenius | 1 |
| n-able | 1 |
| naichen | 1 |
| otrs | 1 |
| xianrendzw | 1 |