We have discovered 235,022 live websites that are affected by CWE-78.
| 41,401 websites | |
| 79,905 websites | |
| 14,477 websites | |
| 11,388 websites | |
| 7,448 websites | |
| 7,372 websites | |
| 6,771 websites | |
| 5,124 websites | |
| 4,563 websites | |
| 4,345 websites |
| .com | 80,626 websites |
| .fr | 33,198 websites |
| .ru | 12,471 websites |
| .org | 9,890 websites |
| .net | 7,157 websites |
| .de | 6,740 websites |
| .nl | 6,637 websites |
| .com.br | 6,194 websites |
| .it | 5,233 websites |
| .be | 4,765 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Jul, 2026 | CVE-2026-55420 | Discourse: Remote code execution via pdf uploads | 1,107 |
| Jun, 2026 | CVE-2026-55697 | pnpm: Repository-controlled configDependencies can select a pacquet native install engine | 1 |
| Jun, 2026 | CVE-2026-40079 | Cacti: Command Injection via escape_command() no-op in RRDtool execution | 74 |
| Jun, 2026 | CVE-2026-47294 | Microsoft SharePoint Server Remote Code Execution Vulnerability | 3,020 |
| Apr, 2026 | CVE-2026-41247 | elFinder: Command injection in resize background color parameter when using ImageMagick CLI | 28 |
| Apr, 2026 | CVE-2026-23500 | Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration | 350 |
| Apr, 2026 | CVE-2026-35196 | Chamilo LMS has OS Command Injection via export_all_certificates action | 5 |
| Apr, 2026 | CVE-2026-32892 | OS Command Injection in Chamilo LMS 1.11.36 | 11 |
| Mar, 2026 | CVE-2026-33046 | Indico discloses local files resulting in Remote Code Execution through LaTeX injection | 62 |
| Mar, 2026 | CVE-2025-50193 | Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database parameter | 11 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Oct, 2024 | CVE-2024-8926 | PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass) | 199,450 |
| Jun, 2024 | CVE-2024-4577 | Argument Injection in PHP-CGI | 165,946 |
| Nov, 2025 | CVE-2025-9501 | W3 Total Cache < 2.8.13 - Unauthenticated Command Injection | 16,496 |
| Oct, 2024 | CVE-2024-45720 | Apache Subversion: Command line argument injection on Windows platforms | 5,512 |
| May, 2024 | CVE-2024-2662 | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command Injection | 3,591 |
| Jun, 2026 | CVE-2026-47294 | Microsoft SharePoint Server Remote Code Execution Vulnerability | 3,020 |
| Feb, 2026 | CVE-2025-12122 | Popup Box – Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting | 1,707 |
| Jul, 2026 | CVE-2026-55420 | Discourse: Remote code execution via pdf uploads | 1,107 |
| Aug, 2024 | CVE-2024-39401 | Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) | 825 |
| Aug, 2024 | CVE-2024-39402 | Adobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) | 825 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.****.com | *** | ||
| ****************.com | *,*** | ||
| ********.********.it | *,*** | ||
| *******.com | *,*** | ||
| ***.int | *,*** | ||
| **********.dk | *,*** | ||
| ******.gov | *,*** | ||
| *********.com | *,*** | ||
| ***************.org | *,*** | ||
| ***.de | *,*** |