Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-178

Improper Handling of Case Sensitivity

The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

85
Assigned CVEs
193rd
Commonality Rank
7.3
Avg CVSS
1.2%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-178 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1998
28 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

85 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-12812CRITICAL
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted
Jul 24, 20209.889YESNO
CVE-2021-24347HIGH
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be execu
Jun 14, 20218.875NOYES
CVE-2025-27636MEDIUM
Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4,
Mar 9, 20255.669NONO
CVE-2018-9845CRITICAL
Etherpad Lite before 1.6.4 is exploitable for admin access.
Apr 29, 20189.848NOYES
CVE-2001-0766CRITICAL
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by
Oct 18, 20019.844NOYES
CVE-2026-40453CRITICAL
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'C
Apr 27, 20269.941NONO
CVE-2003-0411HIGH
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase
Jun 30, 20037.541NOYES
CVE-2026-53595CRITICAL
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenCo
Jul 20, 20269.440NONO
CVE-2026-54763CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoof
Jul 6, 202610.040NONO
CVE-2026-47323CRITICAL
Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf
May 19, 20269.840NONO
View all 85 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
13%
19%
5.0-5.9
16%
6.0-6.9
31%
26%
7.0-7.9
16%
11%
8.0-8.9
22%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
1.2% of CVEs· 92nd percentile
Metasploit
1 CVE
1.2% of CVEs· 89th percentile
Nuclei
2 CVEs
2.4% of CVEs· 90th percentile
ExploitDB
5 CVEs
5.9% of CVEs· 96th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products