CWE-345
Insufficient Verification of Data Authenticity
Description
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701
CVEs mapped to this weakness (809)
page 28 of 41| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43666 | Med | 0.35 | 6.5 | 0.00 | Oct 16, 2023 | Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve… | ||
| CVE-2023-26467 | Med | 0.35 | 5.4 | 0.01 | Apr 10, 2023 | A man in the middle can redirect traffic to a malicious server in a compromised configuration. | ||
| CVE-2023-23940 | Med | 0.35 | 6.4 | 0.00 | Feb 3, 2023 | OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signature`. As a result, any contract using… | ||
| CVE-2022-31598 | Med | 0.35 | 5.4 | 0.00 | Jul 12, 2022 | Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on… | ||
| CVE-2020-11985 | Med | 0.35 | 5.3 | 0.07 | Aug 7, 2020 | IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24… | ||
| CVE-2020-15699 | Med | 0.35 | 5.3 | 0.01 | Jul 15, 2020 | An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration. | ||
| CVE-2019-12620 | Med | 0.35 | 5.3 | 0.01 | Sep 18, 2019 | A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An… | ||
| CVE-2019-5431 | Med | 0.35 | 5.4 | 0.00 | May 6, 2019 | This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login… | ||
| CVE-2015-9232 | Med | 0.35 | 5.3 | 0.01 | Sep 20, 2017 | The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names… | ||
| CVE-2026-78296 | Med | 0.34 | 5.3 | 0.00 | Sep 17, 2026 | Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2. | ||
| CVE-2026-92360 | Med | 0.34 | 6.3 | 0.00 | Sep 16, 2026 | A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote… | ||
| CVE-2026-84906 | Med | 0.34 | 5.3 | 0.00 | Sep 16, 2026 | The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing… | ||
| CVE-2026-86809 | Med | 0.34 | 5.3 | 0.00 | Sep 11, 2026 | The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment… | ||
| CVE-2026-83537 | Med | 0.34 | 5.3 | 0.00 | Sep 9, 2026 | The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | ||
| CVE-2026-84043 | Med | 0.34 | 5.3 | 0.00 | Sep 4, 2026 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature. | ||
| CVE-2026-84767 | Med | 0.34 | 5.3 | 0.00 | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | ||
| CVE-2026-83533 | Med | 0.34 | 5.3 | 0.00 | Sep 2, 2026 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying. | ||
| CVE-2026-16650 | Med | 0.34 | 5.3 | 0.00 | Aug 21, 2026 | The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment. | ||
| CVE-2026-15150 | Med | 0.34 | 5.3 | 0.00 | Aug 21, 2026 | The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site's in-site currency credited to an… | ||
| CVE-2026-15239 | Med | 0.34 | 5.3 | 0.00 | Aug 7, 2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated… |
- risk 0.35cvss 6.5epss 0.00
Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve…
- risk 0.35cvss 5.4epss 0.01
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
- risk 0.35cvss 6.4epss 0.00
OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signature`. As a result, any contract using…
- risk 0.35cvss 5.4epss 0.00
Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on…
- risk 0.35cvss 5.3epss 0.07
IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24…
- risk 0.35cvss 5.3epss 0.01
An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.
- risk 0.35cvss 5.3epss 0.01
A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An…
- risk 0.35cvss 5.4epss 0.00
This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login…
- risk 0.35cvss 5.3epss 0.01
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names…
- risk 0.34cvss 5.3epss 0.00
Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.
- risk 0.34cvss 6.3epss 0.00
A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote…
- risk 0.34cvss 5.3epss 0.00
The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing…
- risk 0.34cvss 5.3epss 0.00
The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment…
- risk 0.34cvss 5.3epss 0.00
The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
- risk 0.34cvss 5.3epss 0.00
The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
- risk 0.34cvss 5.3epss 0.00
The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
- risk 0.34cvss 5.3epss 0.00
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.
- risk 0.34cvss 5.3epss 0.00
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site's in-site currency credited to an…
- risk 0.34cvss 5.3epss 0.00
The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated…