VYPR

CWE-348

Use of Less Trusted Source

BaseDraft

Description

The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-141 · CAPEC-142 · CAPEC-73 · CAPEC-76 · CAPEC-85

CVEs mapped to this weakness (69)

page 2 of 4
  • CVE-2022-4537MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login…

  • CVE-2022-2255HigAug 25, 2022
    risk 0.42cvss 7.5epss 0.01

    A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.

  • CVE-2026-44046MedJun 19, 2026
    risk 0.38cvss 5.8epss 0.00

    Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based access control rules. This issue affects Apache APISIX: from…

  • CVE-2026-24910MedJan 27, 2026
    risk 0.38cvss 5.9epss 0.00

    In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).

  • CVE-2020-37248MedJun 8, 2026
    risk 0.35cvss 6.5epss 0.00

    OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.

  • CVE-2026-40226MedApr 10, 2026
    risk 0.35cvss 6.4epss 0.00

    In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.

  • CVE-2026-35507MedApr 3, 2026
    risk 0.35cvss 6.4epss 0.00

    Shynet before 0.14.0 allows Host header injection in the password reset flow.

  • CVE-2022-4539MedAug 31, 2024
    risk 0.35cvss 5.3epss 0.01

    The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers…

  • CVE-2024-44930MedAug 29, 2024
    risk 0.35cvss 6.5epss 0.00

    Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

  • CVE-2026-22201MedMar 13, 2026
    risk 0.34cvss 5.3epss 0.00

    wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP…

  • CVE-2025-13694MedJan 7, 2026
    risk 0.34cvss 5.3epss 0.00

    The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This is due to the plugin trusting user-supplied headers such as HTTP_X_FORWARDED_FOR to determine the client's IP address without proper validation or…

  • CVE-2025-15154MedDec 28, 2025
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The…

  • CVE-2025-53522MedAug 20, 2025
    risk 0.34cvss 5.3epss 0.00

    Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unauthenticated attacker.

  • CVE-2025-47149MedMay 23, 2025
    risk 0.34cvss 5.3epss 0.00

    The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If exploited, the product may treat an unauthorized pattern file as an authorized. If the product uses a specially crafted pattern file, information in the server…

  • CVE-2022-4533MedSep 19, 2024
    risk 0.34cvss 5.3epss 0.00

    The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers…

  • CVE-2022-4529MedSep 5, 2024
    risk 0.34cvss 5.3epss 0.00

    The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login…

  • CVE-2022-4536MedAug 31, 2024
    risk 0.34cvss 5.3epss 0.00

    The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can…

  • CVE-2024-0789MedJun 19, 2024
    risk 0.34cvss 5.3epss 0.00

    The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for…

  • CVE-2026-26927MedApr 2, 2026
    risk 0.33cvss epss 0.00

    Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched. In Szafir SDK Web it is possible to change the URL (HTTP Origin) of the application call location. An unauthenticated attacker can craft a website that is…

  • CVE-2026-3635MedMar 23, 2026
    risk 0.33cvss 6.1epss 0.00

    Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto and X-Forwarded-Host headers from any…