boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-89

Weakness type CWE-89 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
130912948

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅██▆

2025-09 1 · 2025-10 0 · 2025-11 0 · 2025-12 2 · 2026-01 3 · 2026-02 2 · 2026-03 8 · 2026-04 6 · 2026-05 201 · 2026-06 401 · 2026-07 389 · 2026-08 284

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2019-74817.5100.0KEVSonicWall SMA100
CVE-2026-90829.899.8KEVDrupal core - Highly critical - SQL injection - SA-CORE-2026-004
CVE-2017-183629.899.7KEVKaseya Virtual System/Server Administrator (VSA)
CVE-2026-601375.999.4KEVWordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
CVE-2024-434689.899.1KEVMicrosoft Configuration Manager Remote Code Execution Vulnerability
CVE-2021-200169.898.4KEVSonicWall SSLVPN SMA100
CVE-2026-7289810.095.4KEVMetabase SQL injection via password reset endpoint
CVE-2020-295749.891.1KEVSophos CyberoamOS
CVE-2026-479927.297.2Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('S…
CVE-2026-209478.897.0Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-481345.690.5SQL injection issue in UserCheck Portal when DLP Software Blade is active
CVE-2026-481364.189.9Authenticated Administrator Role-Based Access Control Bypass in Compliance
CVE-2026-171918.585.5VeloCloud Orchestrator Flow Metrics API SQL Injection
CVE-2026-351528.881.8Apache Fineract: SQL injection in runreports endpoint
CVE-2025-3411210.079.1Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE
CVE-2026-33268.677.6XStore < 9.7.3 - Unauthenticated SQLi
CVE-2026-466709.874.6YesWiki: Unauthenticated SQL Injection
CVE-2026-805410.073.6Unauthenticated SQL Injection in dotCMS Publish Audit API
CVE-2026-118408.873.6SQL Injection
CVE-2026-446807.671.3MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
itsourcecode79
sourcecodester70
code-projects56
helmholz40
mb connect line40
codeastro36
open ises17
koha community12
ibm11
apache9
dell9
10web8
aiopmsd8
guardian7
microsoft7