The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Volume of CVEs assigned to CWE-178 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12812CRITICAL An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted | Jul 24, 2020 | 9.8 | 89 | YES | NO |
CVE-2021-24347HIGH The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be execu | Jun 14, 2021 | 8.8 | 75 | NO | YES |
CVE-2025-27636MEDIUM Bypass/Injection vulnerability in Apache Camel components under particular conditions.
This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, | Mar 9, 2025 | 5.6 | 69 | NO | NO |
CVE-2018-9845CRITICAL Etherpad Lite before 1.6.4 is exploitable for admin access. | Apr 29, 2018 | 9.8 | 48 | NO | YES |
CVE-2001-0766CRITICAL Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by | Oct 18, 2001 | 9.8 | 44 | NO | YES |
CVE-2026-40453CRITICAL The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'C | Apr 27, 2026 | 9.9 | 41 | NO | NO |
CVE-2003-0411HIGH Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase | Jun 30, 2003 | 7.5 | 41 | NO | YES |
CVE-2026-53595CRITICAL FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenCo | Jul 20, 2026 | 9.4 | 40 | NO | NO |
CVE-2026-54763CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoof | Jul 6, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-47323CRITICAL Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering
The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf | May 19, 2026 | 9.8 | 40 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.