Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-98
Weakness type CWE-98 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 194 | 191 | 2 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▃▃▂▁
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 10 · 2026-06 102 · 2026-07 36 · 2026-08 22 · 2026-09 18 · 2026-10 3
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-68645 | 8.8 | 98.8 | KEV | Synacor Zimbra Collaboration Suite (ZCS) |
| CVE-2026-87902 | 8.1 | 98.8 | KEV | — |
| CVE-2026-85200 | 7.5 | 87.8 | — | GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion |
| CVE-2026-12227 | 9.8 | 86.3 | — | Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via '… |
| CVE-2026-44177 | 8.8 | 77.4 | — | Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup |
| CVE-2024-14002 | 7.1 | 69.2 | — | Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis |
| CVE-2026-13080 | 6.6 | 67.3 | — | WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' … |
| CVE-2026-17605 | 6.6 | 67.3 | — | Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticate… |
| CVE-2026-8134 | 9.4 | 64.8 | — | Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemp… |
| CVE-2026-14280 | 6.6 | 60.4 | — | Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'db… |
| CVE-2026-15338 | 7.5 | 60.2 | — | LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File … |
| CVE-2026-7515 | 9.8 | 59.6 | — | BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style |
| CVE-2026-9559 | 9.9 | 59.1 | — | — |
| CVE-2026-27555 | 8.8 | 57.9 | — | Local File Inclusion in /index.php/ajax/get_iodd_port_info |
| CVE-2026-27556 | 8.8 | 57.9 | — | Local File Inclusion in /index.php/ajax/save_iodd_parameters |
| CVE-2026-9662 | 8.1 | 57.8 | — | Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion via 'tpf' … |
| CVE-2026-75963 | 7.5 | 57.4 | — | Events Made Easy <= 3.2.5 - Authenticated (Contributor+) Local File Inclusion via 'wp_p… |
| CVE-2025-11977 | 6.6 | 57.3 | — | HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion |
| CVE-2026-9200 | 7.5 | 56.1 | — | Query Shortcode <= 0.2.1 - Authenticated (Contributor+) Local File Inclusion via 'lens'… |
| CVE-2026-7522 | 8.8 | 55.6 | — | Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Local File I… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| themerex | 53 |
| elated-themes | 11 |
| select-themes | 9 |
| axiomthemes | 7 |
| mikado-themes | 5 |
| arraytics | 3 |
| edge-themes | 3 |
| invoiceplane | 3 |
| stylemixthemes | 3 |
| thememove | 3 |
| uxper | 3 |
| webgeniuslab | 3 |
| carlo gavazzi automation | 2 |
| pepperl+fuchs | 2 |
| phoenix contact | 2 |