VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (809)

page 28 of 41
  • CVE-2023-43666MedOct 16, 2023
    risk 0.35cvss 6.5epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General user can view all user data like Admin account. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve…

  • CVE-2023-26467MedApr 10, 2023
    risk 0.35cvss 5.4epss 0.01

    A man in the middle can redirect traffic to a malicious server in a compromised configuration.

  • CVE-2023-23940MedFeb 3, 2023
    risk 0.35cvss 6.4epss 0.00

    OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling `verify_eth_signature`. As a result, any contract using…

  • CVE-2022-31598MedJul 12, 2022
    risk 0.35cvss 5.4epss 0.00

    Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on…

  • CVE-2020-11985MedAug 7, 2020
    risk 0.35cvss 5.3epss 0.07

    IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24…

  • CVE-2020-15699MedJul 15, 2020
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.

  • CVE-2019-12620MedSep 18, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to inject arbitrary values on an affected device. The vulnerability is due to insufficient authentication for the statistics collection service. An…

  • CVE-2019-5431MedMay 6, 2019
    risk 0.35cvss 5.4epss 0.00

    This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login…

  • CVE-2015-9232MedSep 20, 2017
    risk 0.35cvss 5.3epss 0.01

    The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names…

  • CVE-2026-78296MedSep 17, 2026
    risk 0.34cvss 5.3epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

  • CVE-2026-92360MedSep 16, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START causes origin validation error. Remote…

  • CVE-2026-84906MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing…

  • CVE-2026-86809MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment…

  • CVE-2026-83537MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.

  • CVE-2026-84043MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature.

  • CVE-2026-84767MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.

  • CVE-2026-83533MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.

  • CVE-2026-16650MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.

  • CVE-2026-15150MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site's in-site currency credited to an…

  • CVE-2026-15239MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated…