boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-98

Weakness type CWE-98 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
1941912

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▃▃▂▁

2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 10 · 2026-06 102 · 2026-07 36 · 2026-08 22 · 2026-09 18 · 2026-10 3

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-686458.898.8KEVSynacor Zimbra Collaboration Suite (ZCS)
CVE-2026-879028.198.8KEV—
CVE-2026-852007.587.8—GEO my WP <= 4.5.5.3 - Unauthenticated Local File Inclusion
CVE-2026-122279.886.3—Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via '…
CVE-2026-441778.877.4—Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup
CVE-2024-140027.169.2—Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis
CVE-2026-130806.667.3—WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' …
CVE-2026-176056.667.3—Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticate…
CVE-2026-81349.464.8—Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemp…
CVE-2026-142806.660.4—Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'db…
CVE-2026-153387.560.2—LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File …
CVE-2026-75159.859.6—BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
CVE-2026-95599.959.1——
CVE-2026-275558.857.9—Local File Inclusion in /index.php/ajax/get_iodd_port_info
CVE-2026-275568.857.9—Local File Inclusion in /index.php/ajax/save_iodd_parameters
CVE-2026-96628.157.8—Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion via 'tpf' …
CVE-2026-759637.557.4—Events Made Easy <= 3.2.5 - Authenticated (Contributor+) Local File Inclusion via 'wp_p…
CVE-2025-119776.657.3—HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
CVE-2026-92007.556.1—Query Shortcode <= 0.2.1 - Authenticated (Contributor+) Local File Inclusion via 'lens'…
CVE-2026-75228.855.6—Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Local File I…

Most-affected vendors