VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,759)

page 136 of 138
  • CVE-2026-25930MedFeb 25, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based Form (LBF) printable view accepts `formid` and `visitid` (or `patientid`) from the request and does not verify that the form belongs…

  • CVE-2026-25929MedFeb 25, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document controller’s `patient_picture` context serves the patient’s photo by document ID or patient ID without verifying that the current…

  • CVE-2026-25220MedFeb 25, 2026
    risk 0.00cvss 6.5epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Message Center accepts the URL parameter `show_all=yes` and passes it to `getPnotesByUser()`, which returns all internal messages (all users’…

  • CVE-2026-27705MedFeb 25, 2026
    risk 0.00cvss 6.5epss 0.00

    Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/asset/v2.py` (lines 579–593) performs a global asset lookup using only the asset ID (`pk`) via `FileAsset.objects.get(id=pk)`,…

  • CVE-2026-3185MedFeb 25, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the argument messageId results in authorization bypass. The attack can be launched…

  • CVE-2026-25530MedFeb 10, 2026
    risk 0.00cvss 4.3epss 0.00

    Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks project-level authorization, allowing authenticated users to access swimlane data from projects they cannot access. This vulnerability is fixed in 1.2.50.

  • CVE-2026-24900MedFeb 9, 2026
    risk 0.00cvss 6.5epss 0.00

    MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, the courses/<:course_id>/assignments/<:assignment_id>/submissions/html_content accepted a select_file_id parameter to serve SubmissionFile objects containing a record of files…

  • CVE-2026-24136HigJan 24, 2026
    risk 0.00cvss 7.5epss 0.00

    Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulnerability that allows unauthenticated actors to extract sensitive information in plain text. Orders…

  • CVE-2026-23844MedJan 19, 2026
    risk 0.00cvss 4.3epss 0.00

    Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulnerability. A user can update/create account balances in other users' bank accounts. Version 0.1.5 fixes the issue.

  • CVE-2025-64516HigJan 15, 2026
    risk 0.00cvss 7.5epss 0.00

    GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GLPI documents attached to any item (ticket, asset, ...). If the public FAQ is enabled, this unauthorized access can be performed by an anonymous user. This…

  • CVE-2025-34437HigDec 17, 2025
    risk 0.00cvss 8.8epss 0.00

    AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.

  • CVE-2025-34436HigDec 17, 2025
    risk 0.00cvss 8.8epss 0.00

    AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.

  • CVE-2025-34435MedDec 17, 2025
    risk 0.00cvss 6.5epss 0.00

    AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the…

  • CVE-2025-64012MedDec 16, 2025
    risk 0.00cvss 4.3epss 0.00

    InvoicePlane commit debb446c is vulnerable to Incorrect Access Control. The invoices/view handler fails to verify ownership before returning invoice data.

  • CVE-2025-66558LowDec 5, 2025
    risk 0.00cvss 3.1epss 0.00

    Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols.…

  • CVE-2025-66556LowDec 5, 2025
    risk 0.00cvss 3.5epss 0.00

    Nextcloud talk is a video & audio conferencing app for Nextcloud. Prior to 20.1.8 and 21.1.2, a participant with chat permissions was able to delete poll drafts of other participants within the conversation based on their numeric ID. This vulnerability is fixed in 20.1.8 and…

  • CVE-2025-66553MedDec 5, 2025
    risk 0.00cvss 4.3epss 0.00

    Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7…

  • CVE-2025-66513MedDec 5, 2025
    risk 0.00cvss 4.3epss 0.00

    Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability…

  • CVE-2025-66547MedDec 5, 2025
    risk 0.00cvss 4.3epss 0.00

    Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.

  • CVE-2025-66546LowDec 5, 2025
    risk 0.00cvss 3.3epss 0.00

    Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.