The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
Volume of CVEs assigned to CWE-1321 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
537 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0230CRITICAL Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. | Sep 14, 2020 | 9.8 | 94 | NO | YES |
CVE-2026-34621HIGH Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerab | Apr 11, 2026 | 8.6 | 80 | YES | NO |
CVE-2019-11358MEDIUM jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob | Apr 20, 2019 | 6.1 | 78 | NO | YES |
CVE-2020-7774CRITICAL The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. | Nov 17, 2020 | 9.8 | 70 | NO | NO |
CVE-2022-24760CRITICAL Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects | Mar 12, 2022 | 10.0 | 60 | NO | NO |
CVE-2022-39396CRITICAL Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnera | Nov 10, 2022 | 9.8 | 52 | NO | NO |
CVE-2021-23450CRITICAL All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. | Dec 17, 2021 | 9.8 | 51 | NO | NO |
CVE-2022-2564CRITICAL Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6. | Jul 28, 2022 | 9.8 | 48 | NO | NO |
CVE-2011-10019CRITICAL Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via th | Aug 13, 2025 | 9.8 | 47 | NO | YES |
CVE-2019-16328HIGH In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default con | Oct 3, 2019 | 7.5 | 42 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.