CWE-178: CWE-178

15
Total CVEs
3
Critical
8
High
7.7
Avg CVSS

Yearly Trend

2026
3
2025
6
2024
2
2023
2
2022
1

Top Affected Vendors

1 Chamilo 1
2 Apache 1
3 Anysphere 1
4 Traefik 1
5 Filebrowser 1
6 Opennetworking 1
7 Drupal 1
8 Vitejs 1
9 Flask Cors Project 1
10 Smartypantsplugins 1

All CWE-178 CVEs (15)

CVE-2023-3545
9.8

This vulnerability allows unauthenticated attackers to bypass file upload security in Chamilo LMS on Windows/Apache systems by uploading a malicious ....

Nov 28, 2023
CVE-2022-29604
9.8

This vulnerability in ONOS (Open Network Operating System) causes improper handling of case sensitivity in device IDs, leading to misleading CORRUPT s...

Apr 20, 2023
CVE-2026-27588
9.1

Caddy servers with host lists exceeding 100 entries have a case-sensitivity vulnerability in the HTTP host matcher. Attackers can bypass host-based ro...

Feb 24, 2026
CVE-2021-24347
8.8

This vulnerability allows authenticated users to upload malicious PHP files by changing the file extension case (e.g., 'php' to 'pHP'), bypassing the ...

Jun 14, 2021
CVE-2024-55634
8.1

This vulnerability in Drupal Core allows attackers to escalate privileges, potentially gaining administrative access to Drupal sites. It affects Drupa...

Dec 10, 2024
CVE-2025-59944
8.0

This vulnerability in Cursor IDE allows attackers to bypass case-sensitive file protection checks on case-insensitive filesystems. By exploiting promp...

Oct 3, 2025
CVE-2026-29054
7.5

This vulnerability allows remote unauthenticated attackers to bypass Traefik's protection mechanisms and remove critical X-Forwarded headers that iden...

Mar 5, 2026
CVE-2024-6866
7.5

This vulnerability in flask-cors 4.01 allows unauthorized origins to bypass CORS restrictions due to case-insensitive path matching. Attackers can acc...

Mar 20, 2025
CVE-2024-23331
7.5

This vulnerability allows attackers to bypass Vite's server.fs.deny file access restrictions on case-insensitive file systems (like Windows) by using ...

Jan 19, 2024
CVE-2021-45893
7.5

Softwarebuero Zauner ARC 4.2.0.4 has improper case sensitivity handling in password authentication, making brute-force attacks more effective by reduc...

Apr 5, 2022
CVE-2025-46701
7.3

This vulnerability in Apache Tomcat's CGI servlet allows attackers to bypass security constraints by exploiting improper case sensitivity handling in ...

May 29, 2025
CVE-2025-50864
6.5

An origin validation error in the elysia-cors library allows attackers to bypass CORS restrictions by using malicious domains that contain legitimate ...

Aug 20, 2025
CVE-2026-25889
5.4

A case-sensitivity flaw in File Browser's password validation allows authenticated users to change passwords without providing the current password. B...

Feb 9, 2026
CVE-2025-4035
4.3

A vulnerability in libsoup allows malicious websites to bypass public suffix protections and set cookies for domains they don't own when the domain co...

Apr 29, 2025
CVE-2025-67718
N/A

CVE-2025-67718 is a path handling vulnerability in Form.io that allows attackers to bypass authentication and access protected API endpoints. Unauthen...

Dec 11, 2025

About CWE-178 (CWE-178)

Our database tracks 15 CVEs classified as CWE-178, with 3 rated critical and 8 rated high severity. The average CVSS score for CWE-178 vulnerabilities is 7.7.

External reference: View CWE-178 on MITRE CWE →

Monitor CWE-178 Vulnerabilities

Get alerted when new CWE-178 CVEs affect your infrastructure.

Start Monitoring Free