We have discovered 24,892 live websites that are affected by CWE-289.
| 5,593 websites | |
| 2,425 websites | |
| 1,791 websites | |
| 1,709 websites | |
| 1,701 websites | |
| 1,642 websites | |
| 999 websites | |
| 861 websites | |
| 763 websites |
| .com | 8,747 websites |
| .ch | 2,329 websites |
| .org | 1,781 websites |
| .it | 1,401 websites |
| .de | 1,072 websites |
| .net | 972 websites |
| .ca | 435 websites |
| .es | 407 websites |
| .jp | 400 websites |
| .fr | 381 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Aug, 2026 | CVE-2026-32639 | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads | 1 |
| Aug, 2026 | CVE-2026-8457 | WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT | 510 |
| Jul, 2026 | CVE-2026-10842 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability | 5 |
| Jul, 2026 | CVE-2026-9701 | Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation | 231 |
| Jun, 2026 | CVE-2026-56091 | Apache Shiro: Authentication bypass in Guice-Web integration | 15,112 |
| Jun, 2024 | CVE-2024-2098 | Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary | 9,036 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Jun, 2026 | CVE-2026-56091 | Apache Shiro: Authentication bypass in Guice-Web integration | 15,112 |
| Jun, 2024 | CVE-2024-2098 | Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary | 9,036 |
| Aug, 2026 | CVE-2026-8457 | WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT | 510 |
| Jul, 2026 | CVE-2026-9701 | Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation | 231 |
| Jul, 2026 | CVE-2026-10842 | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability | 5 |
| Aug, 2026 | CVE-2026-32639 | Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads | 1 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.***.org | *,*** | ||
| ********.org | *,*** | ||
| ****************.ch | *,*** | ||
| ****.edu | **,*** | ||
| ***********.com | **,*** | ||
| ********.********.edu | **,*** | ||
| ****.********.org | **,*** | ||
| ****.****.***.edu | **,*** | ||
| ****.****.edu | **,*** | ||
| *******.org | **,*** |