boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-838

Weakness type CWE-838 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
550

Monthly trend

▃█▃▁

2026-07 1 · 2026-08 3 · 2026-09 1 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-558585.957.6—MariaDB Connector/J: Inappropriate Encoding for Output Context in org.mariadb.jdbc:mari…
CVE-2026-558595.939.9—MariaDB Connector/R2DBC: Inappropriate Encoding for Output Context and Improper Encodin…
CVE-2026-536414.836.5—FOSSBilling has stored XSS in client email views via unescaped content in JavaScript te…
CVE-2026-470792.17.8—Round-trip Corruption via Improper Entity Escaping in xml_builder
CVE-2026-844636.33.7—Zammad: Stored HTML injection in Knowledge Base video widget enables forced session swi…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
mariadb-corporation2
fossbilling1
joshnuss1
org.mariadb1
zammad1