CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2025-49125 HIGH
Apache Tomcat 9.0.0-9.0.105, 10.1.0-M1-10.1.41, 11.0.0-M1-11.0.7 - Authentication Bypass
CVSS 7.5
CVE-2025-4973 CRITICAL
Workreap <= 3.3.1 - Unauthenticated Authentication Bypass via Email Verification
CVSS 9.8
CVE-2025-30184 CRITICAL
CyberData 011209 Intercom - Info Disclosure
CVSS 9.8
CVE-2025-31022 CRITICAL
PayU PayU India <3.8.8 - Auth Bypass
CVSS 9.8
CVE-2025-31019 HIGH
miniOrange Password Policy Manager <2.0.4 - Auth Bypass
CVSS 8.8
CVE-2025-48904 MEDIUM
HarmonyOS - Unauthorized API Access in FRS Process
CVSS 4.4
CVE-2025-4797 CRITICAL
Golo - City Travel Guide WordPress Theme <1.7.0 - Privilege Escalation
CVSS 9.8
CVE-2025-5190 HIGH
Browse As plugin <0.2 - Auth Bypass
CVSS 8.8
CVE-2025-4687 HIGH
Teltonika Networks RMS <5.7 - Privilege Escalation
CVE-2025-48926 MEDIUM
TeleMessage < 2025-05-05 - Unauthenticated Authentication Bypass via Admin Panel
CVSS 4.3
CVE-2025-47461 HIGH
mediaticus Subaccounts for WooCommerce <1.6.6 - Auth Bypass
CVSS 8.8
CVE-2025-34026 HIGH KEV
Versa Concerto <12.2.0 - Auth Bypass
CVSS 7.5
CVE-2025-46412 CRITICAL
Vertiv Liebert RDU101 < 1.9.0.0 and Liebert IS-UNITY < 8.4.1.0 - Authentication Bypass
CVSS 9.8
CVE-2025-48011 MEDIUM
Drupal One Time Password < 8.x-1.3 - Authentication Bypass via Alternate Path
CVSS 4.8
CVE-2025-48010 MEDIUM
Drupal One Time Password 8.x-1.0-8.x-1.2 - Authentication Bypass
CVSS 4.8
CVE-2025-47941 HIGH
TYPO3 <12.4.31 LTS & <13.4.2 LTS - Auth Bypass
CVSS 7.2
CVE-2025-47710 HIGH
miniorange_2fa 5.0.0-5.1.9 - Authentication Bypass via Alternate Path
CVSS 7.4
CVE-2025-47707 HIGH
miniorange_2fa 5.0.0-5.2.0 - Authentication Bypass via Alternate Path
CVSS 7.5
CVE-2025-3932 MEDIUM
Thunderbird < 128.10.1, < 138.0.1 - XSS
CVSS 6.5
CVE-2025-4427 MEDIUM KEV
Ivanti Endpoint Manager Mobile <= 12.5.0.0 - Unauthenticated Authentication Bypass via API
CVSS 5.3
CVE-2025-22462 CRITICAL
Ivanti Neurons for ITSM < 2023.4, 2024.2, 2024.3 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2025-40581 HIGH
SCALANCE LPE9403 - Authentication Bypass via SINEMA Remote Connect Edge Client
CVSS 7.1
CVE-2025-0549 MEDIUM
GitLab CE/EE <17.9.8, <17.10.6, <17.11.2 - Auth Bypass
CVSS 6.8
CVE-2025-3844 CRITICAL
PeproDev Ultimate Profile Solutions <7.5.2 - Auth Bypass
CVSS 9.8
CVE-2025-45607 CRITICAL
itranswarp v2.19 - Authentication Bypass via /manage/ Request
CVSS 9.8
Details
Vulnerabilities 612