Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-87 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 5 | 0 |
█▆▁
2026-06 3 · 2026-07 2 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-54002 | 8.5 | 34.3 | — | Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::saniti… |
| CVE-2026-25688 | 6.1 | 34.0 | — | Apache Answer: XSS in AI Answer Rendering |
| CVE-2026-55237 | 8.8 | 24.8 | — | AutoGPT SignUp Page has DOM-Based XSS and Open Redirect |
| CVE-2026-55661 | 4.8 | 15.3 | — | TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing sto… |
| CVE-2026-46492 | 6.1 | 14.3 | — | md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed) |
| Vendor | CVEs |
|---|---|
| apache | 1 |
| commenthol | 1 |
| getkirby | 1 |
| significant-gravitas | 1 |
| tinacms | 1 |