Cyber Resilience

CWE · MITRE source

CWE-791Incomplete Filtering of Special Elements

Abstraction: Base · CVEs in our corpus: 40

The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-47323 7.69.80.01542026-05-19
CVE-2025-0324 7.09.40.00342025-06-02
CVE-2024-47590 6.78.80.00762024-11-12
CVE-2022-2132 6.68.60.01782022-08-31
CVE-2022-21668 6.28.00.03902022-01-10
CVE-2024-27489 5.87.50.00412024-07-19
CVE-2026-71645.87.50.00432026-04-30
CVE-2025-6761 5.77.30.00372025-06-27
CVE-2026-29186 5.77.70.00782026-03-07
CVE-2026-11998 5.77.60.00332026-06-24
CVE-2025-2040 5.06.30.00472025-03-06
CVE-2025-5325 5.06.30.00462025-05-29
CVE-2025-14731 5.06.30.00442025-12-16
CVE-2026-48208 5.06.50.00332026-06-01
CVE-2025-6518 4.96.30.00332025-06-23
CVE-2026-37254.96.30.00402026-03-08
CVE-2026-5559 4.96.30.00312026-04-05
CVE-2026-9498 4.96.30.00292026-05-25
CVE-2026-18632 4.96.30.00382026-08-03
CVE-2026-199294.96.30.00282026-08-16
CVE-2026-759794.96.30.00312026-08-19
CVE-2026-8740 4.86.30.00232026-05-17
CVE-2025-59303 4.76.40.00242025-10-08
CVE-2024-39899 4.55.30.00632024-07-09
CVE-2024-39283 4.56.00.00182024-08-14