CWE-830: Inclusion of Web Functionality from an Untrusted Source
The product includes web functionality (such as a web widget) from another domain, which causes it to operate within the domain of the product, potentially granting total access and control of the product to the untrusted source.
10 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-65109 — Minder does not sandbox http.send in Rego programs
- CVE-2025-64496 — Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
- CVE-2025-46652 — In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archiv
- CVE-2025-43703 — An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access
- CVE-2025-33028 — In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.
- CVE-2025-33027 — In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers
- CVE-2025-33026 — In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass
Recently published
- CVE-2025-65109 — Minder does not sandbox http.send in Rego programs
- CVE-2025-64496 — Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
- CVE-2025-46652 — In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archiv
- CVE-2025-43703 — An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access
- CVE-2025-33028 — In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811.
- CVE-2025-33027 — In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers
- CVE-2025-33026 — In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass