VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,759)

page 120 of 138
  • CVE-2022-3995MedNov 29, 2022
    risk 0.21cvss 4.3epss 0.01

    The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it possible for authenticated…

  • CVE-2022-2080MedAug 29, 2022
    risk 0.21cvss 4.3epss 0.01

    The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to send messages to arbitrary private conversation via a IDOR attack. Note: Attackers are not able to…

  • CVE-2022-1810MedMay 23, 2022
    risk 0.21cvss 4.3epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.

  • CVE-2017-18878MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. Knowledge of a session ID allows revoking another user's session.

  • CVE-2019-19259MedJan 3, 2020
    risk 0.21cvss 4.3epss 0.01

    GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).

  • CVE-2026-81654LowSep 20, 2026
    risk 0.20cvss 3.1epss 0.00

    The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply…

  • CVE-2026-81651LowSep 20, 2026
    risk 0.20cvss 3.1epss 0.00

    The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including…

  • CVE-2026-81182MedSep 18, 2026
    risk 0.20cvss 4.2epss 0.00

    SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared note to reference the target asset…

  • CVE-2026-68493LowSep 18, 2026
    risk 0.20cvss 3.1epss 0.00

    After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

  • CVE-2026-73657MedAug 13, 2026
    risk 0.20cvss 4.2epss 0.00

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.findUnique({ where: { friendlyId: runParam…

  • CVE-2026-43883MedMay 11, 2026
    risk 0.20cvss 4.2epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.json.php cancels a PayPal billing agreement using an attacker-supplied agreement parameter without verifying that the authenticated user owns the agreement. A…

  • CVE-2026-35624MedApr 9, 2026
    risk 0.20cvss 4.2epss 0.00

    OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit similarly named rooms to bypass allowlist policies and gain unauthorized access to protected Nextcloud…

  • CVE-2026-35617MedApr 9, 2026
    risk 0.20cvss 4.2epss 0.00

    OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by changing or colliding space display names to gain unauthorized access to protected…

  • CVE-2026-4958LowMar 27, 2026
    risk 0.20cvss 3.1epss 0.01

    A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentServer/application/websockets/replayer.py of the component WebSocket Endpoint. Such manipulation of the argument interaction_id…

  • CVE-2026-4549LowMar 22, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack…

  • CVE-2026-2366LowMar 12, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker…

  • CVE-2025-68492MedJan 14, 2026
    risk 0.20cvss 4.2epss 0.00

    Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.

  • CVE-2025-12918LowNov 9, 2025
    risk 0.20cvss 3.1epss 0.00

    A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file /dashboard/fees/fee-invoices/ of the component View Fee Invoice. Performing manipulation of the argument invoice_id results in…

  • CVE-2025-12623LowNov 3, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this issue is some unknown functionality of the file fuint-application/src/main/java/com/fuint/module/clientApi/controller/ClientSignController.java of the component…

  • CVE-2025-8447LowAug 26, 2025
    risk 0.20cvss 3.1epss 0.00

    An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any repository to retrieve limited code content from another repository by creating a diff between the repositories. To exploit this vulnerability, an attacker…