VYPR

CWE-345

Insufficient Verification of Data Authenticity

ClassDraft

Description

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-148 · CAPEC-218 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-665 · CAPEC-701

CVEs mapped to this weakness (720)

page 30 of 36
  • CVE-2020-13265MedJun 19, 2020
    risk 0.28cvss 4.3epss 0.01

    User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

  • CVE-2019-15971MedNov 26, 2019
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the MP3 detection engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validation of certain MP3 file…

  • CVE-2018-10894MedAug 1, 2018
    risk 0.28cvss 5.4epss 0.00

    It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.

  • CVE-2018-2434MedJul 10, 2018
    risk 0.28cvss 4.3epss 0.01

    A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP…

  • CVE-2017-13083MedOct 18, 2017
    risk 0.28cvss 5.3epss 0.01

    Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attacker to easily convince a user to execute arbitrary code

  • CVE-2026-7792MedJun 6, 2026
    risk 0.27cvss 5.3epss 0.00

    The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint…

  • CVE-2026-9189MedMay 29, 2026
    risk 0.27cvss 5.3epss 0.00

    The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by…

  • CVE-2026-44999MedMay 11, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue to strengthen prompt-injection attacks…

  • CVE-2026-6498MedApr 30, 2026
    risk 0.27cvss 5.3epss 0.00

    The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id…

  • CVE-2026-3177MedApr 7, 2026
    risk 0.27cvss 5.3epss 0.00

    The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and including, 1.8.9.7. This is due to missing cryptographic verification of…

  • CVE-2026-34511MedApr 3, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling…

  • CVE-2026-33221MedMar 20, 2026
    risk 0.27cvss 5.3epss 0.00

    Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload handler trusts the client-provided Content-Type header without performing server-side MIME type detection. This allows an attacker to upload files with an…

  • CVE-2026-32029MedMar 19, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate from configured trusted proxies, allowing attackers to spoof client IP addresses. In proxy chains that append or preserve header values, attackers can inject…

  • CVE-2026-2385MedFeb 22, 2026
    risk 0.27cvss 5.3epss 0.00

    The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and…

  • CVE-2025-14444MedFeb 18, 2026
    risk 0.27cvss 5.3epss 0.00

    The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification of data authenticity on the 'process_paypal_sdk_payment' function in all versions up to, and…

  • CVE-2026-0939MedJan 16, 2026
    risk 0.27cvss 5.3epss 0.00

    The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verification of data authenticity in all versions up to, and including, 5.1.2. This is due to the plugin failing to verify the authenticity of payment callbacks.…

  • CVE-2025-24882MedJan 29, 2025
    risk 0.27cvss 5.2epss 0.00

    regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.

  • CVE-2024-35175MedMay 14, 2024
    risk 0.27cvss 5.3epss 0.00

    sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in sshpiper can allow an attacker to forge their connecting address. Commit 2ddd69876a1e1119059debc59fe869cb4e754430 added the proxy…

  • CVE-2024-27305MedMar 12, 2024
    risk 0.27cvss 5.3epss 0.00

    aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on not so novel interpretation differences of the SMTP protocol. By exploiting SMTP smuggling, an…

  • CVE-2023-45292MedDec 11, 2023
    risk 0.27cvss 5.3epss 0.00

    When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to…