Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-943
Weakness type CWE-943 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 71 | 71 | 0 |
Monthly trend
▁▄▃▇█▂
2026-05 1 · 2026-06 10 · 2026-07 6 · 2026-08 23 · 2026-09 26 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-62906 | 7.4 | 59.7 | — | Microsoft Discovery Studio Information Disclosure Vulnerability |
| CVE-2026-53674 | 7.1 | 49.8 | — | BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution |
| CVE-2026-10698 | 7.2 | 49.1 | — | Table scope bypass vulnerability in custom reports |
| CVE-2026-46591 | 8.2 | 44.1 | — | Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties heade… |
| CVE-2026-54350 | 9.8 | 43.3 | — | Budibase: Anonymous NoSQL operator injection via published-app query templates |
| CVE-2026-55253 | 7.7 | 42.9 | — | LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-ten… |
| CVE-2026-40141 | 8.5 | 42.8 | — | High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support … |
| CVE-2026-45689 | 9.1 | 42.6 | — | Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary Use… |
| CVE-2026-77070 | 7.1 | 41.5 | — | n8n before 1.123.69 NoSQL Injection via MongoDB Node |
| CVE-2026-76316 | 8.8 | 41.0 | — | Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise |
| CVE-2026-73618 | 8.7 | 41.0 | — | Budibase Server before 3.40.0 NoSQL Injection via JSON Parameter |
| CVE-2026-45688 | 9.1 | 40.2 | — | Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAM… |
| CVE-2026-44840 | 7.5 | 40.1 | — | Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query |
| CVE-2026-81525 | 8.6 | 39.9 | — | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP… |
| CVE-2026-88031 | 6.1 | 39.2 | — | GridFS data deletion via query-operator injection in file IDs in the MongoDB Go Driver |
| CVE-2026-88023 | 6.1 | 38.9 | — | GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon… |
| CVE-2026-88024 | 6.1 | 38.9 | — | GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon… |
| CVE-2026-88025 | 6.1 | 38.9 | — | GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon… |
| CVE-2026-88029 | 6.1 | 38.9 | — | GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon… |
| CVE-2026-88030 | 6.1 | 38.9 | — | GridFS data disclosure and deletion via query-operator injection in file IDs in the Mon… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| mongodb | 19 |
| splunk | 8 |
| n8n-io | 4 |
| spring | 4 |
| ash-project | 3 |
| budibase | 3 |
| 4turesearchdata | 2 |
| apache | 2 |
| dgraph-io | 2 |
| langchain-ai | 2 |
| progress | 2 |
| rocketchat | 2 |
| typo3 | 2 |
| beyondtrust | 1 |
| buddypress | 1 |