The product does not use, or incorrectly uses, an input validation framework that is provided by the source language or an independent library.
Volume of CVEs assigned to CWE-1173 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33454CRITICAL The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' | Apr 27, 2026 | 9.4 | 40 | NO | NO |
CVE-2022-1414HIGH 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain access | Oct 19, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-58360MEDIUM stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create | Jul 16, 2026 | 6.5 | 27 | NO | NO |
CVE-2025-3940CRITICAL Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data | May 22, 2025 | 9.8 | 25 | NO | NO |
CVE-2020-1640HIGH An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (routing protocols process) daemon allows an attacker to crash RP | Jul 17, 2020 | 7.5 | 25 | NO | NO |
CVE-2023-29091HIGH An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exyno | Apr 14, 2023 | 7.5 | 24 | NO | NO |
CVE-2026-33674MEDIUM PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known | Mar 26, 2026 | 5.3 | 19 | NO | NO |
CVE-2025-48490MEDIUM Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be s | May 30, 2025 | 6.6 | 19 | NO | NO |
CVE-2023-30949MEDIUM A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks. | Jul 26, 2023 | 5.3 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.