The product does not return custom error pages to the user, possibly exposing sensitive information.
Volume of CVEs assigned to CWE-756 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3175MEDIUM Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2. | Sep 13, 2022 | 5.3 | 20 | NO | NO |
CVE-2018-8913MEDIUM Missing custom error page vulnerability in Synology Web Station before 2.1.3-0139 allows remote attackers to conduct phishing attacks via a crafted URL. | Apr 1, 2019 | 6.1 | 20 | NO | NO |
CVE-2023-27998MEDIUM A lack of custom error pages vulnerability [CWE-756] in FortiPresence versions 1.2.0 through 1.2.1 and all versions of 1.1 and 1.0 may allow an unauthenticated attacker with the ab | Sep 13, 2023 | 5.3 | 16 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.