Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-838
Weakness type CWE-838 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 5 | 0 |
Monthly trend
▃█▃▁
2026-07 1 · 2026-08 3 · 2026-09 1 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-55858 | 5.9 | 57.6 | — | MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mari… |
| CVE-2026-55859 | 5.9 | 39.9 | — | MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encodin… |
| CVE-2026-53641 | 4.8 | 36.5 | — | FOSSBilling has stored XSS in client email views via unescaped content in JavaScript te… |
| CVE-2026-47079 | 2.1 | 7.8 | — | Round-trip Corruption via Improper Entity Escaping in xml_builder |
| CVE-2026-84463 | 6.3 | 3.7 | — | Zammad: Stored HTML injection in Knowledge Base video widget enables forced session swi… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| mariadb-corporation | 2 |
| fossbilling | 1 |
| joshnuss | 1 |
| org.mariadb | 1 |
| zammad | 1 |