CWE-230: Improper Handling of Missing Values
The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.
Last updated
Overview
CWE-230 (Improper Handling of Missing Values) is a variant-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
12 recorded CVEs are caused by CWE-230 (Improper Handling of Missing Values). The highest-severity and most recent are shown first. 4 new CWE-230 CVEs have been recorded so far in 2026 (1 in 2025).
- CVE-2024-11024
AppPresser – Mobile App Framework <= 4.4.6 - Unauthenticated Privilege Escalation via Password Reset
Critical · CVSS 9.8 · EPSS 61th2024-11-26 - CVE-2024-10508
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
Critical · CVSS 9.8 · EPSS 95th2024-11-09 - CVE-2026-20086High · CVSS 8.6 · EPSS 36th