Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

537
Assigned CVEs
75th
Commonality Rank
8.3
Avg CVSS
0.2%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-1321 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2018
8 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

537 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-0230CRITICAL
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Sep 14, 20209.894NOYES
CVE-2026-34621HIGH
Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerab
Apr 11, 20268.680YESNO
CVE-2019-11358MEDIUM
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source ob
Apr 20, 20196.178NOYES
CVE-2020-7774CRITICAL
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
Nov 17, 20209.870NONO
CVE-2022-24760CRITICAL
Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects
Mar 12, 202210.060NONO
CVE-2022-39396CRITICAL
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnera
Nov 10, 20229.852NONO
CVE-2021-23450CRITICAL
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Dec 17, 20219.851NONO
CVE-2022-2564CRITICAL
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
Jul 28, 20229.848NONO
CVE-2011-10019CRITICAL
Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via th
Aug 13, 20259.847NOYES
CVE-2019-16328HIGH
In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default con
Oct 3, 20197.542NOYES
View all 537 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
11%
16%
6.0-6.9
20%
26%
7.0-7.9
14%
11%
8.0-8.9
44%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
0.2% of CVEs· 81st percentile
Metasploit
3 CVEs
0.6% of CVEs· 84th percentile
Nuclei
4 CVEs
0.7% of CVEs· 83rd percentile
ExploitDB
4 CVEs
0.7% of CVEs· 79th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products