Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-915

MITRE ↗

CWE-915

18
CRITICAL
51
HIGH
33
MEDIUM
2
LOW
119 CVEs · Page 3/3
4.2
CVE-2026-15083

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Cond

3.7
CVE-2026-23522

LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKno

2.7
CVE-2026-24140

MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignme

CVE-2026-22814

@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assi

CVE-2026-46721

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on th

CVE-2026-45058

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is

CVE-2026-56276

Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated

CVE-2026-55736

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a

CVE-2026-55223

c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can c

CVE-2026-50281

Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw

CVE-2026-43925

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass

CVE-2026-56679

9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body t

CVE-2026-69258

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthentic

CVE-2026-17598

Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when

CVE-2026-62315

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/clie

CVE-2026-78416

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex

CVE-2026-77144

The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the

CVE-2026-78038

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban all

8.8
CVE-2019-9057

An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call

Frequently Asked Questions

What is CWE-915?

CWE-915 (CWE-915) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-915?

There are 122 CVE records associated with CWE-915 in our database. Of these, 18 are critical severity, 51 are high severity, and 33 are medium severity.

How can I protect against CWE-915 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-915 using AI-powered security agents.

Detect CWE-915 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-915 vulnerabilities across your infrastructure.

Get Started