VYPR

CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains

VariantIncomplete

Description

The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (120)

page 3 of 6
  • CVE-2026-33010HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.00

    mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_credentials=True,…

  • CVE-2026-33043HigMar 20, 2026
    risk 0.46cvss 8.1epss 0.00

    WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthenticated request. The allowOrigin() function reflects any Origin header back in Access-Control-Allow-Origin with…

  • CVE-2026-32610HigMar 18, 2026
    risk 0.46cvss 8.1epss 0.00

    Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combined with `allow_credentials=True`. When both of these options are enabled…

  • CVE-2025-25234HigApr 17, 2025
    risk 0.46cvss 7.1epss 0.00

    Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.

  • CVE-2024-41659HigAug 20, 2024
    risk 0.46cvss 8.1epss 0.01

    memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request,…

  • CVE-2023-46281HigDec 12, 2023
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation Portal (TIA Portal) V14 (All versions),…

  • CVE-2026-70604HigAug 5, 2026
    risk 0.45cvss 7.4epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was not subject to CORS enforcement. A page…

  • CVE-2024-10315MedNov 11, 2024
    risk 0.45cvss epss 0.00

    In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.

  • CVE-2024-32862MedAug 1, 2024
    risk 0.44cvss 6.8epss 0.00

    Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

  • CVE-2023-45213MedFeb 6, 2024
    risk 0.43cvss 6.6epss 0.00

    A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the device.

  • CVE-2026-34200HigMar 31, 2026
    risk 0.42cvss 7.5epss 0.00

    Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when explicitly configured to listen on a network port, applies no inbound authentication and does not enforce strict CORS. This allows a malicious website visited on…

  • CVE-2026-24435MedJan 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets Access-Control-Allow-Origin: * in combination with…

  • CVE-2025-55462MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker-controlled Origin header to be reflected in the Access-Control-Allow-Origin response along with Access-Control-Allow-Credentials: true. This permits malicious third-party websites to…

  • CVE-2025-10529MedSep 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

  • CVE-2025-25264MedJun 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.

  • CVE-2024-6449MedAug 28, 2024
    risk 0.42cvss 6.5epss 0.00

    HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote…

  • CVE-2023-37526MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.00

    HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning…

  • CVE-2022-34366MedFeb 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

  • CVE-2019-14860MedNov 8, 2019
    risk 0.42cvss 6.5epss 0.01

    It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.

  • CVE-2026-46608HigJun 25, 2026
    risk 0.41cvss 7.4epss 0.00

    Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE-2026-33533. However, the implementation silently falls back to…