We have discovered 11,181 live websites that are affected by CWE-1287.
| 2,965 websites | |
| 1,222 websites | |
| 1,163 websites | |
| 1,150 websites | |
| 606 websites | |
| 538 websites | |
| 461 websites | |
| 430 websites | |
| 355 websites | |
| 228 websites |
| .com | 3,859 websites |
| .co.uk | 791 websites |
| .de | 761 websites |
| .org | 638 websites |
| .nl | 519 websites |
| .ch | 518 websites |
| .com.au | 377 websites |
| .jp | 323 websites |
| .net | 297 websites |
| .ca | 247 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| May, 2026 | CVE-2026-4646 | Insufficient input validation in GitHub plugin API causes denial of service | 118 |
| May, 2026 | CVE-2026-7887 | For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status | 10,952 |
| Mar, 2026 | CVE-2026-2454 | DoS in Calls plugin via malformed msgpack in websocket request. | 76 |
| Mar, 2026 | CVE-2026-25783 | Denial of service via malformed User-Agent header in getBrowserVersion | 76 |
| Dec, 2025 | CVE-2025-12689 | DoS in Calls plugin via malformed UTF-8 in WebSocket request | 41 |
| Dec, 2025 | CVE-2025-13352 | Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking | 24 |
| Oct, 2025 | CVE-2025-58084 | Mattermost Desktop App crashes when clicking on malformed external URL | 16 |
| Aug, 2025 | CVE-2025-8402 | Nil pointer dereference in bulk import crashes server | 34 |
| Apr, 2025 | CVE-2025-41395 | Webapp DoS via malicious retrospective post in Playbooks | 14 |
| Jan, 2025 | CVE-2025-20621 | Webapp crash via object that can't be cast to String in Attachment Field | 10 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| May, 2026 | CVE-2026-7887 | For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status | 10,952 |
| May, 2026 | CVE-2026-4646 | Insufficient input validation in GitHub plugin API causes denial of service | 118 |
| Mar, 2026 | CVE-2026-2454 | DoS in Calls plugin via malformed msgpack in websocket request. | 76 |
| Mar, 2026 | CVE-2026-25783 | Denial of service via malformed User-Agent header in getBrowserVersion | 76 |
| Dec, 2025 | CVE-2025-12689 | DoS in Calls plugin via malformed UTF-8 in WebSocket request | 41 |
| Aug, 2025 | CVE-2025-8402 | Nil pointer dereference in bulk import crashes server | 34 |
| Dec, 2025 | CVE-2025-13352 | Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking | 24 |
| Dec, 2024 | CVE-2024-54083 | DoS via lack of type validation in Calls | 17 |
| Oct, 2025 | CVE-2025-58084 | Mattermost Desktop App crashes when clicking on malformed external URL | 16 |
| Apr, 2025 | CVE-2025-41395 | Webapp DoS via malicious retrospective post in Playbooks | 14 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.com | **,*** | ||
| ****************.org | **,*** | ||
| *****.**.jp | **,*** | ||
| **.*********.jp | **,*** | ||
| ***.****.*****.**.us | **,*** | ||
| ******.*******.edu | ***,*** | ||
| ***.*********.jp | ***,*** | ||
| *************.org | ***,*** | ||
| ****.*******.edu | ***,*** | ||
| *************************************************.***.au | ***,*** |