boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-87

Weakness type CWE-87 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
770

Monthly trend

█▆▁▆▁

2026-06 3 · 2026-07 2 · 2026-08 0 · 2026-09 2 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-256886.145.5—Apache Answer: XSS in AI Answer Rendering
CVE-2026-540028.544.0—Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::saniti…
CVE-2026-556614.832.5—TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing sto…
CVE-2026-799465.326.8——
CVE-2026-464926.124.9—md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
CVE-2026-552378.822.7—AutoGPT SignUp Page has DOM-Based XSS and Open Redirect
CVE-2026-852934.812.0—InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote M…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache1
commenthol1
dell1
getkirby1
invoiceplane1
significant-gravitas1
tinacms1