CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2025-61673 HIGH
Karapace 5.0.0-5.0.1 - Unauthenticated Authentication Bypass via Missing Authorization Header
CVSS 8.6
CVE-2025-6388 CRITICAL
Spirit Framework plugin - Auth Bypass
CVSS 9.8
CVE-2025-10653 HIGH
Unspecified Product <Version> - Info Disclosure
CVSS 8.6
CVE-2025-22862 MEDIUM
FortiOS 7.0.6-7.4.7 and FortiProxy 7.0.5-7.6.2 - Authenticated Privilege Escalation via Automation Stitch Webhook Action
CVSS 6.7
CVE-2025-61733 HIGH
Apache Kylin 4.0.0-5.0.2 - Authentication Bypass Using an Alternate Path or Channel
CVSS 7.5
CVE-2025-10538 HIGH
LG Innotek Camera Models LND7210 and LNV7210R - Authentication Bypass
CVE-2025-7038 HIGH
LatePoint Calendar Booking Plugin <= 5.1.94 - Unauthenticated Authentication Bypass
CVSS 8.2
CVE-2025-5955 HIGH
Service Finder SMS System <2.0.0 - Auth Bypass
CVSS 8.1
CVE-2025-10531 MEDIUM
Firefox <143 - Privilege Escalation
CVSS 5.4
CVE-2025-8359 CRITICAL
AdForest theme <6.0.9 - Auth Bypass
CVSS 9.8
CVE-2025-57819 CRITICAL KEV
FreePBX 15.0-15.0.65 - Unauthenticated Authentication Bypass and Remote Code Execution
CVSS 9.8
CVE-2025-54738 CRITICAL
NooTheme Jobmonster <4.7.9 - Auth Bypass
CVSS 9.8
CVE-2025-54725 CRITICAL
Golo <= 1.7.0 - Authentication Bypass via Alternate Path
CVSS 9.8
CVE-2025-34520 CRITICAL
Arcserve UDP < 10.2 - Unauthenticated Authentication Bypass via Request Parameter Manipulation
CVSS 9.8
CVE-2025-5821 CRITICAL
Case Theme User <1.0.3 - Auth Bypass
CVSS 9.8
CVE-2025-5060 HIGH
Bravis User <= 1.0.1 - Authentication Bypass via Facebook Login Callback
CVSS 8.1
CVE-2025-7642 CRITICAL
Simpler Checkout 0.7.0-1.1.9 - Auth Bypass
CVSS 9.8
CVE-2025-55623 MEDIUM
Reolink v4.54.0.4.20250526 - Auth Bypass
CVSS 5.4
CVE-2025-50904 CRITICAL
WinterChenS my-site < 2025-06-11 - Unauthenticated Authentication Bypass via /admin/ API
CVSS 9.8
CVE-2025-27129 CRITICAL
Tenda AC6 V5.0 V02.03.01.110 - Auth Bypass
CVSS 9.8
CVE-2025-24496 HIGH
Tenda AC6 V5.0 V02.03.01.110 - Information Disclosure via /goform/getproductInfo
CVSS 7.5
CVE-2025-54713 CRITICAL
Taxi Booking Manager for WooCommerce <1.3.0 - Auth Bypass
CVSS 9.8
CVE-2025-52338 MEDIUM
LogicData eCommerce Framework <5.0.9.7000 - Auth Bypass
CVSS 5.3
CVE-2025-3639 LOW
Liferay Portal 7.3.0-7.4.3.132 & DXP - Unauthenticated Authentication Bypass via POST to GET
CVE-2025-8995 CRITICAL
Authenticator Login < 2.1.4 - Authentication Bypass via Alternate Path
CVSS 9.8
Details
Vulnerabilities 612