CWE-1321


Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.


We have discovered 4,162,754 live websites that are affected by CWE-1321.

Contact us to get more info









CVEs

  • Count - 35



Website Distribution by Country

Number of websites using CWE-1321
United States929,231 websites



Israel1,171,387 websites
Germany260,946 websites
France150,336 websites
GB149,351 websites
Italy106,851 websites
Netherlands95,646 websites
Japan88,426 websites
Brazil87,132 websites
Russia83,066 websites

Website Distribution by TLD

Number of websites using CWE-1321
.com2,037,149 websites
.org207,612 websites
.de170,285 websites
.co.uk146,842 websites
.com.br100,337 websites
.nl96,455 websites
.net94,750 websites
.it82,810 websites
.fr81,344 websites
.com.au74,189 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-1321
DiscoveredCVEDescriptionWebsites
Jul, 2026CVE-2026-54335 Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__6
Jul, 2026CVE-2026-55886 Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()160
Jul, 2026CVE-2026-54756 Jodit Editor: Prototype pollution via Jodit.configure() / ConfigMerge160
Jun, 2026CVE-2026-44490 Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions31,813
Jun, 2026CVE-2026-46625 JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection1,361,772
May, 2026CVE-2026-44966 Velocity.js: Prototype Pollution in #set path assignment1
May, 2026CVE-2026-44292 protobufjs: Prototype injection in generated message constructors245
May, 2026CVE-2026-44290 protobufjs: Process-wide denial of service through unsafe option paths245
May, 2026CVE-2026-42264 Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking18,236
Apr, 2026CVE-2026-42033 Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking31,741
List of the most common CVEs that are part of CWE-1321
DiscoveredCVEDescriptionWebsites
Feb, 2026CVE-2026-27212 Swiper has a Prototype Pollution Vulnerability1,571,107
Jan, 2026CVE-2025-13465 Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions1,467,434
Jun, 2026CVE-2026-46625 JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection1,361,772
Mar, 2026CVE-2026-2950 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`64,735
Jun, 2026CVE-2026-44490 Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions31,813
Apr, 2026CVE-2026-42033 Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking31,741
May, 2026CVE-2026-42264 Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking18,236
Apr, 2025CVE-2025-31475 tarteaucitron.js allows prototype pollution via custom text injection8,110
Oct, 2025CVE-2025-62517 Rollbar.js Prototype Pollution Vulnerability in merge()7,512
Oct, 2024CVE-2024-48910 DOMPurify vulnerable to tampering by prototype polution1,643

Websites affected by CWE-1321

Top websites that are affected by CWE-1321. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*****.com United States***
***.com Israel***
******.net United States***
*****.com United States***
****.me Japan***
***************.org United States***
****.io France***
*******.com United States***
*****.com United States***
****.fr France***
See full domain list