CWE-471: MAID
The product does not properly protect an assumed-immutable element from being modified by an attacker.
34 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-9876 — Application is vulnerable to Privilege escalation
- CVE-2026-54267 — Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
- CVE-2025-33136 — IBM Aspera Faspex data modification
- CVE-2024-34517 — The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al
- CVE-2026-44798 — Nautobot: GitRepository.current_head field should not be writable through REST API
- CVE-2024-51462 — IBM QRadar WinCollect Agent data manipulation
- CVE-2026-8492 — Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035
Recently published
- CVE-2026-54267 — Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
- CVE-2026-44798 — Nautobot: GitRepository.current_head field should not be writable through REST API
- CVE-2026-8492 — Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035
- CVE-2025-33136 — IBM Aspera Faspex data modification
- CVE-2024-9876 — Application is vulnerable to Privilege escalation
- CVE-2024-51462 — IBM QRadar WinCollect Agent data manipulation
- CVE-2024-34517 — The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al