We have discovered 4,162,754 live websites that are affected by CWE-1321.
| 929,231 websites | |
| 1,171,387 websites | |
| 260,946 websites | |
| 150,336 websites | |
| 149,351 websites | |
| 106,851 websites | |
| 95,646 websites | |
| 88,426 websites | |
| 87,132 websites | |
| 83,066 websites |
| .com | 2,037,149 websites |
| .org | 207,612 websites |
| .de | 170,285 websites |
| .co.uk | 146,842 websites |
| .com.br | 100,337 websites |
| .nl | 96,455 websites |
| .net | 94,750 websites |
| .it | 82,810 websites |
| .fr | 81,344 websites |
| .com.au | 74,189 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Jul, 2026 | CVE-2026-54335 | Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__ | 6 |
| Jul, 2026 | CVE-2026-55886 | Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set() | 160 |
| Jul, 2026 | CVE-2026-54756 | Jodit Editor: Prototype pollution via Jodit.configure() / ConfigMerge | 160 |
| Jun, 2026 | CVE-2026-44490 | Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions | 31,813 |
| Jun, 2026 | CVE-2026-46625 | JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection | 1,361,772 |
| May, 2026 | CVE-2026-44966 | Velocity.js: Prototype Pollution in #set path assignment | 1 |
| May, 2026 | CVE-2026-44292 | protobufjs: Prototype injection in generated message constructors | 245 |
| May, 2026 | CVE-2026-44290 | protobufjs: Process-wide denial of service through unsafe option paths | 245 |
| May, 2026 | CVE-2026-42264 | Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking | 18,236 |
| Apr, 2026 | CVE-2026-42033 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking | 31,741 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Feb, 2026 | CVE-2026-27212 | Swiper has a Prototype Pollution Vulnerability | 1,571,107 |
| Jan, 2026 | CVE-2025-13465 | Prototype Pollution Vulnerability in Lodash _.unset and _.omit functions | 1,467,434 |
| Jun, 2026 | CVE-2026-46625 | JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection | 1,361,772 |
| Mar, 2026 | CVE-2026-2950 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` | 64,735 |
| Jun, 2026 | CVE-2026-44490 | Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions | 31,813 |
| Apr, 2026 | CVE-2026-42033 | Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking | 31,741 |
| May, 2026 | CVE-2026-42264 | Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking | 18,236 |
| Apr, 2025 | CVE-2025-31475 | tarteaucitron.js allows prototype pollution via custom text injection | 8,110 |
| Oct, 2025 | CVE-2025-62517 | Rollbar.js Prototype Pollution Vulnerability in merge() | 7,512 |
| Oct, 2024 | CVE-2024-48910 | DOMPurify vulnerable to tampering by prototype polution | 1,643 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.*****.com | *** | ||
| ***.com | *** | ||
| ******.net | *** | ||
| *****.com | *** | ||
| ****.me | *** | ||
| ***************.org | *** | ||
| ****.io | *** | ||
| *******.com | *** | ||
| *****.com | *** | ||
| ****.fr | *** |