VYPR

CWE-472

External Control of Assumed-Immutable Web Parameter

BaseDraft

Description

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-146 · CAPEC-226 · CAPEC-31 · CAPEC-39

CVEs mapped to this weakness (152)

page 6 of 8
  • CVE-2025-29788MedMar 17, 2025
    risk 0.35cvss 6.5epss 0.00

    The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 allows users to manipulate the final payment amount processed by PayPal. If a user modifies the item quantity in their…

  • CVE-2021-27769MedMay 12, 2022
    risk 0.35cvss 5.3epss 0.01

    Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any information that could be used for an…

  • CVE-2019-13927MedDec 12, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with…

  • CVE-2026-84762MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.

  • CVE-2026-77794MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the…

  • CVE-2026-16067MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price.…

  • CVE-2026-15149MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or…

  • CVE-2026-11678MedJun 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-11669MedJun 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-4911MedApr 28, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the…

  • CVE-2025-26312MedMar 14, 2025
    risk 0.34cvss —epss 0.00

    SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.

  • CVE-2024-12123MedDec 4, 2024
    risk 0.34cvss —epss 0.00

    A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user.  When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy.  The ticket requester…

  • CVE-2024-6010MedSep 7, 2024
    risk 0.34cvss 5.3epss 0.00

    The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to the plugin allowing the price field to be manipulated prior to processing via the 'create_cc_order' function, called from the Cost…

  • CVE-2026-11290MedJun 5, 2026
    risk 0.33cvss 5.0epss 0.00

    Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)

  • CVE-2026-11281MedJun 5, 2026
    risk 0.33cvss 5.0epss 0.00

    Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)

  • CVE-2025-67846MedDec 19, 2025
    risk 0.32cvss 4.9epss 0.00

    The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous…

  • CVE-2026-16089MedJul 17, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be…

  • CVE-2026-9911MedMay 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-8567MedMay 14, 2026
    risk 0.28cvss 4.3epss 0.00

    Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-8559MedMay 14, 2026
    risk 0.28cvss 4.3epss 0.00

    Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)