VYPR

CWE-472

External Control of Assumed-Immutable Web Parameter

BaseDraft

Description

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-146 · CAPEC-226 · CAPEC-31 · CAPEC-39

CVEs mapped to this weakness (152)

page 5 of 8
  • CVE-2025-8198HigJul 26, 2025
    risk 0.49cvss 7.5epss 0.00

    The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. This is due to an insufficient check on quantity values when changing quantities in the cart. This makes it…

  • CVE-2025-25382HigMar 10, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.

  • CVE-2025-22384HigJan 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are…

  • CVE-2026-41353HigApr 23, 2026
    risk 0.46cvss 8.1epss 0.00

    OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating…

  • CVE-2025-47245HigMay 4, 2025
    risk 0.46cvss 8.1epss 0.00

    In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.

  • CVE-2021-27770MedMay 12, 2022
    risk 0.44cvss 6.8epss 0.01

    The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can specify an external URL where the online meeting will…

  • CVE-2026-15045MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero,…

  • CVE-2026-14069MedJun 30, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-11044MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-9882MedMay 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-10018MedMay 28, 2026
    risk 0.42cvss 6.5epss 0.00

    Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-39364HigApr 7, 2026
    risk 0.42cvss 7.5epss 0.02

    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or…

  • CVE-2025-3530HigApr 23, 2025
    risk 0.42cvss 7.5epss 0.01

    The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the…

  • CVE-2023-38520MedJun 4, 2024
    risk 0.42cvss 6.5epss 0.00

    External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.

  • CVE-2025-35939MedKEVMay 7, 2025
    risk 0.40cvss 5.3epss 0.01

    Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session…

  • CVE-2026-7571HigMay 19, 2026
    risk 0.39cvss 7.1epss 0.00

    A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clients. By manipulating client data during a session restart, an attacker can…

  • CVE-2026-42655MedJun 15, 2026
    risk 0.38cvss 5.9epss 0.00

    Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.

  • CVE-2023-28512MedMar 3, 2024
    risk 0.38cvss 5.9epss 0.01

    IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improper input validation. IBM X-Force ID: 250396.

  • CVE-2026-84654MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration…

  • CVE-2025-30152MedMar 19, 2025
    risk 0.35cvss 6.5epss 0.00

    The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows users to modify their shopping cart after completing the PayPal Checkout process and payment authorization. If a user…