Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-917
Weakness type CWE-917 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 22 | 16 | 6 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▂▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▃▂█▃▁▃▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 2 · 2026-04 2 · 2026-05 1 · 2026-06 6 · 2026-07 2 · 2026-08 0 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2021-26084 | 9.8 | 100.0 | KEV | Atlassian Confluence Server and Data Center |
| CVE-2022-26134 | 9.8 | 100.0 | KEV | Atlassian Confluence Server/Data Center |
| CVE-2021-45046 | 9.0 | 100.0 | KEV | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a… |
| CVE-2020-10199 | 8.8 | 99.9 | KEV | Sonatype Nexus Repository |
| CVE-2020-17530 | 9.8 | 99.9 | KEV | Apache Struts |
| CVE-2010-1871 | 8.8 | 99.7 | KEV | Red Hat JBoss Seam 2 |
| CVE-2026-40478 | 9.0 | 67.2 | — | Improper neutralization of specific syntax patterns for unauthorized expressions in Thy… |
| CVE-2026-40477 | 9.0 | 59.7 | — | Improper restriction of the scope of accessible objects in Thymeleaf expressions |
| CVE-2026-52439 | 9.8 | 59.1 | — | — |
| CVE-2026-33938 | 8.1 | 56.5 | — | Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block |
| CVE-2026-44209 | 7.5 | 52.9 | — | Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI |
| CVE-2026-65591 | 8.9 | 51.3 | — | n8n before 1.123.64 Sanitizer Bypass Remote Code Execution |
| CVE-2026-8888 | 7.5 | 46.9 | — | CVE-2026-8888 |
| CVE-2026-24737 | 8.1 | 46.8 | — | jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Exec… |
| CVE-2026-11561 | 9.8 | 36.8 | — | SSTI in Soagen Informatics' Apinizer |
| CVE-2026-91145 | 7.1 | 34.3 | — | Activiti through 7.1.0.M6 Expression Injection via Mail Task |
| CVE-2026-41717 | 8.1 | 34.2 | — | Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding |
| CVE-2026-41729 | 8.1 | 32.0 | — | Spring Data REST SpEL Injection via Map Key in JSON Patch |
| CVE-2026-34714 | 8.6 | 19.6 | — | — |
| CVE-2026-40985 | 6.4 | 19.4 | — | Data Binding Vulnerability in Spring Web Flow with Unified EL Parser |