Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-915
Weakness type CWE-915 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 92 | 92 | 0 |
Monthly trend
▁▂▃█▇▆▆▂
2026-03 1 · 2026-04 5 · 2026-05 6 · 2026-06 24 · 2026-07 19 · 2026-08 18 · 2026-09 16 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-50160 | 10.0 | 76.4 | — | Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite |
| CVE-2026-29063 | 8.7 | 75.0 | — | Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Proto… |
| CVE-2026-40175 | 4.8 | 69.6 | — | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| CVE-2026-72710 | 9.3 | 65.1 | — | SPIP < 4.4.18 RCE via editer_objet.php Job Queue Injection |
| CVE-2026-44495 | 7.7 | 62.8 | — | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config… |
| CVE-2026-78416 | 8.7 | 62.2 | — | Authenticated RCE via `condition.config` JSON cleanse bypass |
| CVE-2026-59721 | 7.2 | 61.9 | — | Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection |
| CVE-2026-46625 | 7.5 | 61.1 | — | JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute i… |
| CVE-2026-42264 | 9.1 | 60.4 | — | Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection… |
| CVE-2026-34427 | 8.7 | 60.3 | — | Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save |
| CVE-2026-44494 | 8.7 | 59.3 | — | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| CVE-2026-42033 | 7.4 | 59.1 | — | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request… |
| CVE-2026-42044 | 9.1 | 57.1 | — | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` |
| CVE-2026-47102 | 8.7 | 55.8 | — | LiteLLM < 1.83.10 Privilege Escalation via User Update |
| CVE-2026-42041 | 6.5 | 55.4 | — | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge S… |
| CVE-2026-72778 | 8.7 | 55.2 | — | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
| CVE-2026-84645 | 8.8 | 54.7 | — | — |
| CVE-2026-18617 | 8.8 | 52.8 | — | Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextrapar… |
| CVE-2026-83557 | 5.6 | 52.2 | — | jackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's uns… |
| CVE-2026-93752 | 8.7 | 50.7 | — | CSSOM through 0.5.0 Denial of Service via length Property |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| flowiseai | 11 |
| drupal | 8 |
| axios | 7 |
| fasterxml | 4 |
| ash-project | 3 |
| craftcms | 3 |
| spring | 3 |
| budibase | 2 |
| djust-org | 2 |
| hoppscotch | 2 |
| middleapi | 2 |
| misp | 2 |
| red hat | 2 |
| a2ui-project | 1 |
| berriai | 1 |