boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-80

Weakness type CWE-80 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
45422

Monthly trend

▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃█▆▄

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 17 · 2026-07 11 · 2026-08 8

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2018-199536.197.6KEVQNAP Network Attached Storage (NAS)
CVE-2018-199435.496.9KEVQNAP Network Attached Storage (NAS)
CVE-2026-502296.190.2Apache Tomcat: XSS in number guess example
CVE-2026-758726.950.7HTML Injection in MailerUp double opt-in verification email
CVE-2025-621985.441.1Apache Atlas: Stored XSS in Create Entity page
CVE-2026-528165.439.2Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs le…
CVE-2026-528548.636.2mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser fun…
CVE-2026-732376.136.0Apache Allura: XSS in markdown pipeline
CVE-2026-732386.136.0Apache Allura: XSS in code display
CVE-2026-416117.835.3Visual Studio Code Remote Code Execution Vulnerability
CVE-2026-340335.430.5Apache Answer: HTML Content Injection in Email
CVE-2026-489106.528.0Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
CVE-2026-132255.327.6Stored XSS in ticket confirmation page
CVE-2026-750822.126.1Webkul Bagisto Customer-Registration Notification Email register cross site scripting
CVE-2026-128122.026.1Radware Cyber Controller HTML Report Generation HTML injection
CVE-2026-575328.826.0
CVE-2026-575342.126.0Stored XSS in pretix-pages
CVE-2026-133142.026.0Stored XSS in pretix-digital
CVE-2026-575352.123.5
CVE-2025-80298.123.3javascript: URLs executed on object and embed tags

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache6
pretix6
calcom2
qnap systems2
alaev1
anglesharp1
armiya information technologies ltd. co1
backdropcms1
bolt1
chocobozzz1
cisco1
commenthol1
datacycle-engine1
flowise1
fortinet1