CWE-178: CWE-178
Yearly Trend
Top Affected Vendors
All CWE-178 CVEs (15)
This vulnerability allows unauthenticated attackers to bypass file upload security in Chamilo LMS on Windows/Apache systems by uploading a malicious ....
Nov 28, 2023This vulnerability in ONOS (Open Network Operating System) causes improper handling of case sensitivity in device IDs, leading to misleading CORRUPT s...
Apr 20, 2023Caddy servers with host lists exceeding 100 entries have a case-sensitivity vulnerability in the HTTP host matcher. Attackers can bypass host-based ro...
Feb 24, 2026This vulnerability allows authenticated users to upload malicious PHP files by changing the file extension case (e.g., 'php' to 'pHP'), bypassing the ...
Jun 14, 2021This vulnerability in Drupal Core allows attackers to escalate privileges, potentially gaining administrative access to Drupal sites. It affects Drupa...
Dec 10, 2024This vulnerability in Cursor IDE allows attackers to bypass case-sensitive file protection checks on case-insensitive filesystems. By exploiting promp...
Oct 3, 2025This vulnerability allows remote unauthenticated attackers to bypass Traefik's protection mechanisms and remove critical X-Forwarded headers that iden...
Mar 5, 2026This vulnerability in flask-cors 4.01 allows unauthorized origins to bypass CORS restrictions due to case-insensitive path matching. Attackers can acc...
Mar 20, 2025This vulnerability allows attackers to bypass Vite's server.fs.deny file access restrictions on case-insensitive file systems (like Windows) by using ...
Jan 19, 2024Softwarebuero Zauner ARC 4.2.0.4 has improper case sensitivity handling in password authentication, making brute-force attacks more effective by reduc...
Apr 5, 2022This vulnerability in Apache Tomcat's CGI servlet allows attackers to bypass security constraints by exploiting improper case sensitivity handling in ...
May 29, 2025An origin validation error in the elysia-cors library allows attackers to bypass CORS restrictions by using malicious domains that contain legitimate ...
Aug 20, 2025A case-sensitivity flaw in File Browser's password validation allows authenticated users to change passwords without providing the current password. B...
Feb 9, 2026A vulnerability in libsoup allows malicious websites to bypass public suffix protections and set cookies for domains they don't own when the domain co...
Apr 29, 2025CVE-2025-67718 is a path handling vulnerability in Form.io that allows attackers to bypass authentication and access protected API endpoints. Unauthen...
Dec 11, 2025About CWE-178 (CWE-178)
Our database tracks 15 CVEs classified as CWE-178, with 3 rated critical and 8 rated high severity. The average CVSS score for CWE-178 vulnerabilities is 7.7.
External reference: View CWE-178 on MITRE CWE →
Monitor CWE-178 Vulnerabilities
Get alerted when new CWE-178 CVEs affect your infrastructure.
Start Monitoring Free