The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.
Volume of CVEs assigned to CWE-791 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-47323CRITICAL Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering
The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf | May 19, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-29186CRITICAL Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @bac | Mar 7, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-11998HIGH A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the contex | Jun 24, 2026 | 7.6 | 34 | NO | NO |
CVE-2026-44232HIGH DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3, every IPv6 category bypasses is_url_safe. This vulnerability is | May 12, 2026 | 8.7 | 30 | NO | NO |
CVE-2026-7164HIGH Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic.
Remote attackers can craft packet | Apr 30, 2026 | 7.5 | 30 | NO | NO |
CVE-2022-21668HIGH pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to | Jan 10, 2022 | 8.6 | 29 | NO | NO |
CVE-2026-48208MEDIUM An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email | Jun 1, 2026 | 6.5 | 28 | NO | NO |
CVE-2025-3841CRITICAL A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py | Apr 21, 2025 | 9.8 | 28 | NO | NO |
CVE-2026-3725HIGH A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/b | Mar 8, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-8740MEDIUM A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/Tem | May 17, 2026 | 6.3 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.