VYPR

CWE-472

External Control of Assumed-Immutable Web Parameter

BaseDraft

Description

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-146 · CAPEC-226 · CAPEC-31 · CAPEC-39

CVEs mapped to this weakness (152)

page 8 of 8
  • CVE-2025-32816LowApr 11, 2025
    risk 0.13cvss 3.1epss 0.00

    CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.

  • CVE-2025-27893LowMar 11, 2025
    risk 0.12cvss 1.8epss 0.00

    In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. NOTE: the Supplier analyzed the…

  • CVE-2025-59382LowJun 10, 2026
    risk 0.08cvss —epss 0.00

    QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

  • CVE-2026-1982MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured…

  • CVE-2026-7484MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: before 202606251646.

  • CVE-2026-65052HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured…

  • CVE-2026-56877MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId values to bypass per-user lab launch…

  • CVE-2026-14430HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-14391MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-14389HigJul 1, 2026
    risk 0.00cvss 8.3epss 0.00

    Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-14387CriJul 1, 2026
    risk 0.00cvss 9.6epss 0.00

    Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-13281HigJun 25, 2026
    risk 0.00cvss 8.3epss 0.00

    Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)