Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-80
Weakness type CWE-80 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 72 | 68 | 3 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇▅▆█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 17 · 2026-07 11 · 2026-08 14 · 2026-09 20 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-13965 | 6.3 | 99.5 | KEV | Roundcube Webmail |
| CVE-2018-19953 | 6.1 | 98.1 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2018-19943 | 5.4 | 97.6 | KEV | QNAP Network Attached Storage (NAS) |
| CVE-2026-50229 | 6.1 | 90.4 | — | Apache Tomcat: XSS in number guess example |
| CVE-2026-73237 | 6.1 | 54.9 | — | Apache Allura: XSS in markdown pipeline |
| CVE-2026-73238 | 6.1 | 54.9 | — | Apache Allura: XSS in code display |
| CVE-2026-75872 | 6.9 | 53.0 | — | HTML Injection in MailerUp double opt-in verification email |
| CVE-2026-32773 | 6.1 | 50.7 | — | Apache Spark: XSS Vulnerability in Spark Web 3.5.4 |
| CVE-2026-52816 | 5.4 | 50.6 | — | Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs le… |
| CVE-2026-52774 | 6.1 | 49.7 | — | Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes in YesWiki |
| CVE-2026-52773 | 6.1 | 46.4 | — | Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.p… |
| CVE-2026-52854 | 8.6 | 45.6 | — | mediawiki/maps: Stored XSS through the overlays parameter in the display_map parser fun… |
| CVE-2026-48910 | 6.5 | 44.6 | — | Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing |
| CVE-2026-52741 | 7.5 | 43.3 | — | GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages |
| CVE-2026-59855 | 8.6 | 42.8 | — | SiYuan: Store XSS To Rce via Asset.render |
| CVE-2026-65841 | 5.3 | 42.8 | — | Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-htm… |
| CVE-2026-34033 | 5.4 | 42.1 | — | Apache Answer: HTML Content Injection in Email |
| CVE-2025-62198 | 5.4 | 41.0 | — | Apache Atlas: Stored XSS in Create Entity page |
| CVE-2026-41611 | 7.8 | 41.0 | — | Visual Studio Code Remote Code Execution Vulnerability |
| CVE-2026-73220 | 8.5 | 39.5 | — | CVAT: Stored XSS via annotation guides in audio tasks |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| the wikimedia foundation | 8 |
| apache | 7 |
| pretix | 7 |
| calcom | 2 |
| gocd | 2 |
| ibm | 2 |
| qnap systems | 2 |
| yeswiki | 2 |
| alaev | 1 |
| anglesharp | 1 |
| armiya information technologies ltd. co | 1 |
| backdropcms | 1 |
| bolt | 1 |
| brainstorm force | 1 |
| chocobozzz | 1 |