boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-915

Weakness type CWE-915 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
57570

Monthly trend

▂▃█▇▄

2026-04 2 · 2026-05 5 · 2026-06 21 · 2026-07 19 · 2026-08 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-5016010.096.9Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
CVE-2026-471028.748.6LiteLLM < 1.83.10 Privilege Escalation via User Update
CVE-2026-420446.545.5Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
CVE-2026-561428.844.8
CVE-2026-344278.744.3Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save
CVE-2026-597217.241.9Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
CVE-2026-186178.837.4Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextrapar…
CVE-2026-727788.737.3Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config
CVE-2026-727196.734.3Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter
CVE-2026-125359.832.0Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
CVE-2026-692588.831.6Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `ov…
CVE-2026-170958.331.6IBM i is Affected By Multiple Vulnerabilities in Navigator for i
CVE-2026-562766.029.8Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override
CVE-2026-446357.529.5Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONP…
CVE-2026-584778.829.0Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters
CVE-2026-545155.327.7jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnorePro…
CVE-2026-464787.727.3Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover
CVE-2026-494288.427.1posixshm: system calls can incorrectly free memory of largepage objects
CVE-2026-464757.726.5Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover
CVE-2026-464767.726.5Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template t…

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
flowiseai11
drupal8
fasterxml3
budibase2
craftcms2
hoppscotch2
red hat2
ash-project1
axios1
berriai1
chatwoot1
concrete cms1
dan-in-ca1
decolua1
dfir-iris1