Skip to main content

About CWE-20

Unexpected values can crash a program or drive excessive memory and CPU use. Controlled resource references can expose confidential data, and malicious input can modify data or alter control flow up to arbitrary command execution.

MITRE marks CWE-20 as DISCOURAGED for mapping real-world vulnerabilities due to frequent misuse and its high abstraction level.

MITRE name
Improper Input Validation
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Stable

Mitigations

  • +Use an accept-known-good strategy: define what valid input looks like and reject or transform everything else.
  • +Identify every place untrusted input enters, including parameters, cookies, headers, environment variables, files and data from external systems.
  • +Repeat any client-side checks on the server, since client checks can be bypassed.
  • +Use an input validation framework, while watching for weaknesses introduced by misusing the framework itself.
  • +Consider language-theoretic security (LangSec) techniques that treat parsing as a distinct layer between raw input and internal data.

Detection
Automated static analysis finds some cases, manual review is needed for business-rule validation, and fuzzing helps expose validation errors through crashes or unexpected behavior.

CWE-20 Vulnerabilities

42 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-88771
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
Citrix NetScaler9.51.1%KEV2026-09-27
CVE-2026-93952
Security Advisory 0183
Arista Networks10.01.1%KEV2026-09-22
CVE-2026-12569
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
PTC9.346.0%KEV2026-06-18
CVE-2026-34910
Ubiquiti UniFi OS Improper Input Validation Vulnerability
Ubiquiti Inc10.045.8%KEV2026-05-22
CVE-2026-6973
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Ivanti7.22.5%KEV2026-05-07
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Apache Software Foundation8.815.5%KEV2026-04-07
CVE-2026-32201
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft6.543.4%KEV2026-04-14
CVE-2025-54236
Adobe Commerce | Improper Input Validation (CWE-20)
Adobe9.194.5%KEV2025-09-09
CVE-2025-8876
Command Injection Vulnerability
N-able9.43.4%KEV2025-08-14
CVE-2025-32706
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Microsoft7.82.3%KEV2025-05-13
CVE-2024-21413
Microsoft Outlook Remote Code Execution Vulnerability
Microsoft9.894.7%KEV2024-02-13
CVE-2024-38189
Microsoft Project Remote Code Execution Vulnerability
Microsoft8.88.2%KEV2024-08-13
CVE-2024-30040
Windows MSHTML Platform Security Feature Bypass Vulnerability
Microsoft8.83.9%KEV2024-05-14
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
Palo Alto Networks10.0100.0%KEV2024-04-12
CVE-2023-36563
Microsoft WordPad Information Disclosure Vulnerability
Microsoft6.520.7%KEV2023-10-10
CVE-2023-36761
Microsoft Word Information Disclosure Vulnerability
Microsoft6.519.6%KEV2023-09-12
CVE-2021-25489
Samsung Mobile Devices Improper Input Validation Vulnerability
Samsung Mobile3.30.5%KEV2021-10-06
CVE-2023-2868
Remote Code injection in Barracuda Email Security Gateway
Barracuda9.487.7%KEV2023-05-24
CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
Microsoft9.897.2%KEV2023-03-14
CVE-2018-19949
QNAP NAS File Station Command Injection Vulnerability
QNAP Systems Inc.9.828.6%KEV2020-10-28
CVE-2018-0125
Cisco VPN Routers Remote Code Execution Vulnerability
-9.855.2%KEV2018-02-08
CVE-2018-0147
Cisco Secure Access Control System Java Deserialization Vulnerability
-9.818.2%KEV2018-03-08
CVE-2019-1652
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
Cisco7.295.9%KEV2019-01-24
CVE-2017-12240
Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
-9.813.8%KEV2017-09-28
CVE-2018-0172
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
-8.67.8%KEV2018-03-28
CVE-2018-0173
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
-8.67.6%KEV2018-03-28
CVE-2018-0174
Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability
-8.67.6%KEV2018-03-28
CVE-2018-0158
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
-8.67.2%KEV2018-03-28
CVE-2017-12233
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
-7.57.1%KEV2017-09-28
CVE-2017-12234
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
-7.57.1%KEV2017-09-28
CVE-2017-12235
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
-7.57.1%KEV2017-09-28
CVE-2018-0159
Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability
-7.56.9%KEV2018-03-28
CVE-2017-12319
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability
-5.95.2%KEV2018-03-27
CVE-2022-24086
Adobe Commerce checkout improper input validation leads to remote code execution
Adobe9.899.2%KEV2022-02-16
CVE-2021-35247
Improper Input Validation Vulnerability in Serv-U
SolarWinds4.33.5%KEV2022-01-07
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Apache Software Foundation10.0100.0%KEV2021-12-10
CVE-2020-3452
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
Cisco7.5100.0%KEV2020-07-22
CVE-2018-0296
Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability
-7.599.9%KEV2018-06-07
CVE-2018-0171
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
-7.599.5%KEV2018-03-28
CVE-2020-3161
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
Cisco9.883.9%KEV2020-04-15
CVE-2020-8195
Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
-6.533.0%KEV2020-07-10
CVE-2026-21858
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
n8n-io10.078.2%2026-01-07

Frequently Asked Questions

What is CWE-20?→

CWE-20, Improper Input Validation, is a Class covering products that accept input without confirming it has the properties required for safe and correct processing.

Why does MITRE discourage CWE-20 for CVE mapping?→

MITRE says CWE-20 is often used in low-information reports when a lower-level CWE fits, and it is not useful for trend analysis. It is also misused when the real issue is how input is transformed rather than validated.

How many exploited vulnerabilities are classified as CWE-20?→

This database lists 42 CVE records mapped to CWE-20 by their CVE Numbering Authority. 41 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 4 to known ransomware campaigns. Examples include CVE-2026-88771, CVE-2026-93952, CVE-2026-12569.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.