VYPR

CWE-639

Authorization Bypass Through User-Controlled Key

BaseIncompleteLikelihood: High

Description

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Hierarchy (View 1000)

Parents

Children

CVEs mapped to this weakness (2,334)

page 9 of 117
  • CVE-2026-23754HigJan 21, 2026
    risk 0.57cvss 8.8epss 0.00

    D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary user_id value to retrieve sensitive credential data belonging to other users, including super administrators.…

  • CVE-2025-69274HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.

  • CVE-2025-15001CriJan 6, 2026
    risk 0.57cvss 9.8epss 0.00

    The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible…

  • CVE-2025-14998CriJan 2, 2026
    risk 0.57cvss 9.8epss 0.01

    The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for…

  • CVE-2021-47721HigDec 23, 2025
    risk 0.57cvss 8.8epss 0.00

    Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to…

  • CVE-2025-6574HigNov 1, 2025
    risk 0.57cvss 8.8epss 0.00

    The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it…

  • CVE-2025-5949HigNov 1, 2025
    risk 0.57cvss 8.8epss 0.00

    The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it…

  • CVE-2025-61779HigOct 9, 2025
    risk 0.57cvss epss 0.00

    Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing secrets to them. In versions prior to 0.15.0, the attestation-policy endpoint didn't check if the kbs-client submitting the request was actually authenticated…

  • CVE-2025-6038HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.00

    The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation via password update in all versions up to, and including, 1.4.0. This is due to the plugin not properly validating a user's identity…

  • CVE-2025-7718HigSep 10, 2025
    risk 0.57cvss 8.8epss 0.00

    The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.5.4. This is due to the plugin not properly validating a user's identity prior to updating their…

  • CVE-2025-7049HigSep 10, 2025
    risk 0.57cvss 8.8epss 0.00

    The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 67.7.0 via the 'MJ_gmgt_gmgt_add_user' function due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2025-52389HigSep 8, 2025
    risk 0.57cvss 8.8epss 0.00

    An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access sensitive data for other users via a crafted HTTP request.

  • CVE-2025-55370HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value.

  • CVE-2025-46387HigAug 6, 2025
    risk 0.57cvss 8.8epss 0.00

    CWE-639 Authorization Bypass Through User-Controlled Key

  • CVE-2025-46386HigAug 6, 2025
    risk 0.57cvss 8.8epss 0.00

    CWE-639 Authorization Bypass Through User-Controlled Key

  • CVE-2025-51865HigJul 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.

  • CVE-2025-34140HigJul 22, 2025
    risk 0.57cvss epss 0.01

    An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was…

  • CVE-2025-40650HigMay 26, 2025
    risk 0.57cvss epss 0.00

    Insecure Direct Object Reference (IDOR) vulnerability in Clickedu. This vulnerability could allow an attacker to retrieve information about student report cards.

  • CVE-2025-3810CriMay 9, 2025
    risk 0.57cvss 9.8epss 0.01

    The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the…

  • CVE-2025-3610HigMay 6, 2025
    risk 0.57cvss 8.8epss 0.01

    The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it…