Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-91 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 13 | 12 | 0 |
▂▁▁▁▁█▅▅▂
2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 3 · 2026-07 3 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-40165 | 8.7 | 40.9 | — | authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifi… |
| CVE-2025-1545 | 8.2 | 39.8 | — | WatchGuard Firebox XPath Injection Vulnerability in Web CGI |
| CVE-2026-46490 | 8.7 | 38.8 | — | samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Ass… |
| CVE-2026-41674 | 8.7 | 38.0 | — | xmldom: XML injection through unvalidated DocumentType serialization |
| CVE-2026-41675 | 8.7 | 34.1 | — | xmldom: XML node injection through unvalidated processing instruction serialization |
| CVE-2026-41672 | 8.7 | 29.7 | — | xmldom: XML node injection through unvalidated comment serialization |
| CVE-2026-24329 | 4.9 | 27.5 | — | Wildfly-core: wildfly core: denial of service via malformed payload injection by an aut… |
| CVE-2026-55789 | 8.5 | 22.4 | — | Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, … |
| CVE-2026-47273 | 6.5 | 19.7 | — | pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries |
| CVE-2026-59728 | 4.3 | 19.2 | — | @astrojs/rss: XML Injection via Unescaped RSS Feed Fields |
| CVE-2026-15037 | 2.9 | 18.2 | — | XML injection vulnerability in QDom comment, CDATA and processing-instruction serializa… |
| CVE-2026-53723 | 5.8 | 12.7 | — | guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via C… |
| CVE-2026-11169 | 8.1 | 11.7 | — | — |