Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-87
Weakness type CWE-87 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 7 | 7 | 0 |
Monthly trend
█▆▁▆▁
2026-06 3 · 2026-07 2 · 2026-08 0 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-25688 | 6.1 | 45.5 | — | Apache Answer: XSS in AI Answer Rendering |
| CVE-2026-54002 | 8.5 | 44.0 | — | Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::saniti… |
| CVE-2026-55661 | 4.8 | 32.5 | — | TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing sto… |
| CVE-2026-79946 | 5.3 | 26.8 | — | — |
| CVE-2026-46492 | 6.1 | 24.9 | — | md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed) |
| CVE-2026-55237 | 8.8 | 22.7 | — | AutoGPT SignUp Page has DOM-Based XSS and Open Redirect |
| CVE-2026-85293 | 4.8 | 12.0 | — | InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote M… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 1 |
| commenthol | 1 |
| dell | 1 |
| getkirby | 1 |
| invoiceplane | 1 |
| significant-gravitas | 1 |
| tinacms | 1 |