boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-87

Weakness type CWE-87 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
550

Monthly trend

█▆▁

2026-06 3 · 2026-07 2 · 2026-08 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-540028.534.3Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::saniti…
CVE-2026-256886.134.0Apache Answer: XSS in AI Answer Rendering
CVE-2026-552378.824.8AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
CVE-2026-556614.815.3TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing sto…
CVE-2026-464926.114.3md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache1
commenthol1
getkirby1
significant-gravitas1
tinacms1