VYPR

CWE-290

Authentication Bypass by Spoofing

BaseIncomplete

Description

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-21 · CAPEC-22 · CAPEC-459 · CAPEC-461 · CAPEC-473 · CAPEC-476 · CAPEC-59 · CAPEC-60 · CAPEC-667 · CAPEC-94

CVEs mapped to this weakness (677)

page 25 of 34
  • CVE-2018-8153MedMay 9, 2018
    risk 0.35cvss 5.4epss 0.04

    A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2026-65502MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

  • CVE-2026-32469MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

  • CVE-2026-14840MedAug 1, 2026
    risk 0.34cvss 5.3epss 0.00

    The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited…

  • CVE-2026-34025MedJun 15, 2026
    risk 0.34cvss epss 0.00

    The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability in the login process. The application restricts user logins based on the IP address associated with a branch location, but the client IP address is derived from…

  • CVE-2026-32492MedMar 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue affects My Tickets: from n/a through <= 2.1.1.

  • CVE-2025-48840MedMar 10, 2026
    risk 0.34cvss 5.3epss 0.00

    An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted…

  • CVE-2025-69203MedJan 1, 2026
    risk 0.34cvss 6.3epss 0.00

    Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by themselves and with an information disclosure vulnerability enable convincing social engineering…

  • CVE-2025-58595MedNov 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin-login allows Identity Spoofing.This issue affects All In One Login: from n/a through <= 2.0.8.

  • CVE-2025-61783MedOct 9, 2025
    risk 0.34cvss epss 0.01

    Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, the user could be associated by e-mail even if the `associate_by_email` pipeline was not included. This could lead to account compromise when a third-party…

  • CVE-2024-13685MedMar 4, 2025
    risk 0.34cvss 5.3epss 0.00

    The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate their value to bypass the login limit feature in the Admin and Site Enhancements (ASE) WordPress plugin…

  • CVE-2025-25055MedFeb 18, 2025
    risk 0.34cvss 5.3epss 0.00

    Authentication bypass by spoofing issue exists in FileMegane versions above 1.0.0.0 prior to 3.4.0.0, which may lead to user impersonation. If exploited, restricted file contents may be accessed.

  • CVE-2024-42513MedFeb 10, 2025
    risk 0.34cvss 5.3epss 0.01

    Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.

  • CVE-2025-24628MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in bestwebsoft Google Captcha google-captcha allows Identity Spoofing.This issue affects Google Captcha: from n/a through <= 1.78.

  • CVE-2023-41133MedDec 13, 2024
    risk 0.34cvss 5.3epss 0.01

    Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows Functionality Bypass.This issue affects Secure Admin IP: from n/a through 2.0.

  • CVE-2024-35538MedAug 19, 2024
    risk 0.34cvss 5.3epss 0.01

    Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

  • CVE-2024-41432MedAug 7, 2024
    risk 0.34cvss 5.3epss 0.00

    An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP…

  • CVE-2024-37430MedJul 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0.

  • CVE-2024-6163MedJul 8, 2024
    risk 0.34cvss 5.3epss 0.01

    Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data

  • CVE-2023-52176MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in miniorange Malware Scanner allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Malware Scanner: from n/a through 4.7.1.