The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.
Volume of CVEs assigned to CWE-472 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
138 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-35939MEDIUM Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Cra | May 7, 2025 | 5.3 | 57 | YES | NO |
CVE-2024-25153CRITICAL A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially cr | Mar 13, 2024 | 9.8 | 54 | NO | NO |
CVE-2026-39364HIGH Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2017-5261HIGH In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerabil | Dec 20, 2017 | 8.8 | 41 | NO | YES |
CVE-2026-14430HIGH Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security seve | Jul 1, 2026 | 8.8 | 40 | NO | NO |
CVE-2017-5260HIGH In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console | Dec 20, 2017 | 8.8 | 40 | NO | YES |
CVE-2026-14387CRITICAL Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security sever | Jul 1, 2026 | 9.6 | 37 | NO | NO |
CVE-2026-13281HIGH Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a m | Jun 25, 2026 | 8.3 | 37 | NO | NO |
CVE-2026-11088CRITICAL Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a c | Jun 4, 2026 | 9.6 | 37 | NO | NO |
CVE-2026-7896HIGH Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever | May 6, 2026 | 8.8 | 36 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.