Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-91
Weakness type CWE-91 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 29 | 27 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▄▃▃▃█▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 5 · 2026-06 3 · 2026-07 3 · 2026-08 3 · 2026-09 13 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-0646 | 9.8 | 99.9 | KEV | Microsoft .NET Framework |
| CVE-2026-76979 | 7.7 | 65.2 | — | XML Injection vulnerability |
| CVE-2026-40165 | 8.7 | 50.7 | — | authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifi… |
| CVE-2026-41672 | 8.7 | 49.5 | — | xmldom: XML node injection through unvalidated comment serialization |
| CVE-2026-41674 | 8.7 | 49.5 | — | xmldom: XML injection through unvalidated DocumentType serialization |
| CVE-2026-102116 | 7.2 | 48.8 | — | Kiteworks Email Protection Gateway Path Traversal |
| CVE-2026-41675 | 8.7 | 48.6 | — | xmldom: XML node injection through unvalidated processing instruction serialization |
| CVE-2026-83605 | 8.7 | 47.6 | — | xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed |
| CVE-2026-83607 | 8.7 | 47.6 | — | xmldom: Element name injection via createElement() bypasses requireWellFormed |
| CVE-2026-83608 | 8.7 | 47.6 | — | xmldom: DocType `name` Injection Bypasses requireWellFormed |
| CVE-2026-83616 | 8.7 | 47.6 | — | xmldom: Processing Instruction Target Injection Bypasses requireWellFormed |
| CVE-2026-24329 | 4.9 | 47.0 | — | Wildfly-core: wildfly core: denial of service via malformed payload injection by an aut… |
| CVE-2026-83617 | 8.7 | 45.3 | — | xmldom: requireWellFormed element/attribute name validation is bypassable via an embedd… |
| CVE-2026-83618 | 8.7 | 45.3 | — | xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an emb… |
| CVE-2026-46490 | 8.7 | 45.1 | — | samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Ass… |
| CVE-2026-83609 | 8.7 | 43.7 | — | xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line term… |
| CVE-2025-1545 | 8.2 | 39.3 | — | WatchGuard Firebox XPath Injection Vulnerability in Web CGI |
| CVE-2026-15037 | 2.9 | 36.5 | — | XML injection vulnerability in QDom comment, CDATA and processing-instruction serializa… |
| CVE-2026-65124 | 8.1 | 36.2 | — | — |
| CVE-2026-103044 | 9.8 | 35.8 | — | EasyTimeline should not serve image maps as application/xml |