Improper Input Validation (CWE-20)
CWE-20 applies when a product receives input but does not validate, or wrongly validates, that the input has the properties needed for safe processing. Those properties include sizes, lengths, indexes, offsets, syntax and type, for both raw data and metadata. MITRE discourages mapping vulnerabilities to CWE-20 and recommends lower-level entries when details are available.
About CWE-20
Unexpected values can crash a program or drive excessive memory and CPU use. Controlled resource references can expose confidential data, and malicious input can modify data or alter control flow up to arbitrary command execution.
MITRE marks CWE-20 as DISCOURAGED for mapping real-world vulnerabilities due to frequent misuse and its high abstraction level.
Mitigations
- +Use an accept-known-good strategy: define what valid input looks like and reject or transform everything else.
- +Identify every place untrusted input enters, including parameters, cookies, headers, environment variables, files and data from external systems.
- +Repeat any client-side checks on the server, since client checks can be bypassed.
- +Use an input validation framework, while watching for weaknesses introduced by misusing the framework itself.
- +Consider language-theoretic security (LangSec) techniques that treat parsing as a distinct layer between raw input and internal data.
Detection
Automated static analysis finds some cases, manual review is needed for business-rule validation, and fuzzing helps expose validation errors through crashes or unexpected behavior.
CWE-20 Vulnerabilities
42 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-88771 | A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands | Citrix NetScaler | 9.5 | 1.1% | KEV | 2026-09-27 |
| CVE-2026-93952 | Security Advisory 0183 | Arista Networks | 10.0 | 1.1% | KEV | 2026-09-22 |
| CVE-2026-12569 | Remote Code Execution (RCE) vulnerability in Windchill PDMlink | PTC | 9.3 | 46.0% | KEV | 2026-06-18 |
| CVE-2026-34910 | Ubiquiti UniFi OS Improper Input Validation Vulnerability | Ubiquiti Inc | 10.0 | 45.8% | KEV | 2026-05-22 |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | Ivanti | 7.2 | 2.5% | KEV | 2026-05-07 |
| CVE-2026-34197 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans | Apache Software Foundation | 8.8 | 15.5% | KEV | 2026-04-07 |
| CVE-2026-32201 | Microsoft SharePoint Server Spoofing Vulnerability | Microsoft | 6.5 | 43.4% | KEV | 2026-04-14 |
| CVE-2025-54236 | Adobe Commerce | Improper Input Validation (CWE-20) | Adobe | 9.1 | 94.5% | KEV | 2025-09-09 |
| CVE-2025-8876 | Command Injection Vulnerability | N-able | 9.4 | 3.4% | KEV | 2025-08-14 |
| CVE-2025-32706 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.3% | KEV | 2025-05-13 |
| CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability | Microsoft | 9.8 | 94.7% | KEV | 2024-02-13 |
| CVE-2024-38189 | Microsoft Project Remote Code Execution Vulnerability | Microsoft | 8.8 | 8.2% | KEV | 2024-08-13 |
| CVE-2024-30040 | Windows MSHTML Platform Security Feature Bypass Vulnerability | Microsoft | 8.8 | 3.9% | KEV | 2024-05-14 |
| CVE-2024-3400 | PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect | Palo Alto Networks | 10.0 | 100.0% | KEV | 2024-04-12 |
| CVE-2023-36563 | Microsoft WordPad Information Disclosure Vulnerability | Microsoft | 6.5 | 20.7% | KEV | 2023-10-10 |
| CVE-2023-36761 | Microsoft Word Information Disclosure Vulnerability | Microsoft | 6.5 | 19.6% | KEV | 2023-09-12 |
| CVE-2021-25489 | Samsung Mobile Devices Improper Input Validation Vulnerability | Samsung Mobile | 3.3 | 0.5% | KEV | 2021-10-06 |
| CVE-2023-2868 | Remote Code injection in Barracuda Email Security Gateway | Barracuda | 9.4 | 87.7% | KEV | 2023-05-24 |
| CVE-2023-23397 | Microsoft Outlook Elevation of Privilege Vulnerability | Microsoft | 9.8 | 97.2% | KEV | 2023-03-14 |
| CVE-2018-19949 | QNAP NAS File Station Command Injection Vulnerability | QNAP Systems Inc. | 9.8 | 28.6% | KEV | 2020-10-28 |
| CVE-2018-0125 | Cisco VPN Routers Remote Code Execution Vulnerability | - | 9.8 | 55.2% | KEV | 2018-02-08 |
| CVE-2018-0147 | Cisco Secure Access Control System Java Deserialization Vulnerability | - | 9.8 | 18.2% | KEV | 2018-03-08 |
| CVE-2019-1652 | Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability | Cisco | 7.2 | 95.9% | KEV | 2019-01-24 |
| CVE-2017-12240 | Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability | - | 9.8 | 13.8% | KEV | 2017-09-28 |
| CVE-2018-0172 | Cisco IOS and IOS XE Software Improper Input Validation Vulnerability | - | 8.6 | 7.8% | KEV | 2018-03-28 |
| CVE-2018-0173 | Cisco IOS and IOS XE Software Improper Input Validation Vulnerability | - | 8.6 | 7.6% | KEV | 2018-03-28 |
| CVE-2018-0174 | Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability | - | 8.6 | 7.6% | KEV | 2018-03-28 |
| CVE-2018-0158 | Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability | - | 8.6 | 7.2% | KEV | 2018-03-28 |
| CVE-2017-12233 | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability | - | 7.5 | 7.1% | KEV | 2017-09-28 |
| CVE-2017-12234 | Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability | - | 7.5 | 7.1% | KEV | 2017-09-28 |
| CVE-2017-12235 | Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability | - | 7.5 | 7.1% | KEV | 2017-09-28 |
| CVE-2018-0159 | Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability | - | 7.5 | 6.9% | KEV | 2018-03-28 |
| CVE-2017-12319 | Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability | - | 5.9 | 5.2% | KEV | 2018-03-27 |
| CVE-2022-24086 | Adobe Commerce checkout improper input validation leads to remote code execution | Adobe | 9.8 | 99.2% | KEV | 2022-02-16 |
| CVE-2021-35247 | Improper Input Validation Vulnerability in Serv-U | SolarWinds | 4.3 | 3.5% | KEV | 2022-01-07 |
| CVE-2021-44228 | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | Apache Software Foundation | 10.0 | 100.0% | KEV | 2021-12-10 |
| CVE-2020-3452 | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability | Cisco | 7.5 | 100.0% | KEV | 2020-07-22 |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability | - | 7.5 | 99.9% | KEV | 2018-06-07 |
| CVE-2018-0171 | Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability | - | 7.5 | 99.5% | KEV | 2018-03-28 |
| CVE-2020-3161 | Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability | Cisco | 9.8 | 83.9% | KEV | 2020-04-15 |
| CVE-2020-8195 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability | - | 6.5 | 33.0% | KEV | 2020-07-10 |
| CVE-2026-21858 | n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling | n8n-io | 10.0 | 78.2% | 2026-01-07 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-20?→
CWE-20, Improper Input Validation, is a Class covering products that accept input without confirming it has the properties required for safe and correct processing.
Why does MITRE discourage CWE-20 for CVE mapping?→
MITRE says CWE-20 is often used in low-information reports when a lower-level CWE fits, and it is not useful for trend analysis. It is also misused when the real issue is how input is transformed rather than validated.
How many exploited vulnerabilities are classified as CWE-20?→
This database lists 42 CVE records mapped to CWE-20 by their CVE Numbering Authority. 41 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 4 to known ransomware campaigns. Examples include CVE-2026-88771, CVE-2026-93952, CVE-2026-12569.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.