Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-915 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 57 | 57 | 0 |
▂▃█▇▄
2026-04 2 · 2026-05 5 · 2026-06 21 · 2026-07 19 · 2026-08 10
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-50160 | 10.0 | 96.9 | — | Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite |
| CVE-2026-47102 | 8.7 | 48.6 | — | LiteLLM < 1.83.10 Privilege Escalation via User Update |
| CVE-2026-42044 | 6.5 | 45.5 | — | Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` |
| CVE-2026-56142 | 8.8 | 44.8 | — | — |
| CVE-2026-34427 | 8.7 | 44.3 | — | Vvveb < 1.0.8.1 Privilege Escalation via admin/user/save |
| CVE-2026-59721 | 7.2 | 41.9 | — | Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection |
| CVE-2026-18617 | 8.8 | 37.4 | — | Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextrapar… |
| CVE-2026-72778 | 8.7 | 37.3 | — | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
| CVE-2026-72719 | 6.7 | 34.3 | — | Chatwoot: Cross-Account Resource Transfer via `account_id` Parameter |
| CVE-2026-12535 | 9.8 | 32.0 | — | Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048 |
| CVE-2026-69258 | 8.8 | 31.6 | — | Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `ov… |
| CVE-2026-17095 | 8.3 | 31.6 | — | IBM i is Affected By Multiple Vulnerabilities in Navigator for i |
| CVE-2026-56276 | 6.0 | 29.8 | — | Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override |
| CVE-2026-44635 | 7.5 | 29.5 | — | Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONP… |
| CVE-2026-58477 | 8.8 | 29.0 | — | Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters |
| CVE-2026-54515 | 5.3 | 27.7 | — | jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnorePro… |
| CVE-2026-46478 | 7.7 | 27.3 | — | Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover |
| CVE-2026-49428 | 8.4 | 27.1 | — | posixshm: system calls can incorrectly free memory of largepage objects |
| CVE-2026-46475 | 7.7 | 26.5 | — | Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover |
| CVE-2026-46476 | 7.7 | 26.5 | — | Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template t… |
| Vendor | CVEs |
|---|---|
| flowiseai | 11 |
| drupal | 8 |
| fasterxml | 3 |
| budibase | 2 |
| craftcms | 2 |
| hoppscotch | 2 |
| red hat | 2 |
| ash-project | 1 |
| axios | 1 |
| berriai | 1 |
| chatwoot | 1 |
| concrete cms | 1 |
| dan-in-ca | 1 |
| decolua | 1 |
| dfir-iris | 1 |