CWE-1104: Use of Unmaintained Third Party Components
The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.
Last updated
Overview
CWE-1104 (Use of Unmaintained Third Party Components) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
14 recorded CVEs are caused by CWE-1104 (Use of Unmaintained Third Party Components). The highest-severity and most recent are shown first. 3 new CWE-1104 CVEs have been recorded so far in 2026 (6 in 2025).
- CVE-2025-12104
Incorrect Content-Type Header
Critical · CVSS 10.0 · EPSS 57th2025-10-23 - CVE-2025-10220
Outdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4
Critical · CVSS 9.8 · EPSS 76th2025-09-10 - CVE-2026-41468
Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection
Critical · CVSS 9.3 · EPSS 23th