CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2024-9658 HIGH
School Management System for Wordpress < 93.0.0 - Authenticated Privilege Escalation via User Detail Update Functions
CVSS 8.8
CVE-2024-13182 CRITICAL
WP Directorybox Manager <2.5 - Auth Bypass
CVSS 9.8
CVE-2024-12857 CRITICAL
AdForest < 5.1.8 - Unauthenticated Authentication Bypass via OTP Login
CVSS 9.8
CVE-2024-13181 HIGH
Ivanti Avalanche <6.4.7 - Path Traversal
CVSS 7.3
CVE-2024-13179 HIGH
Ivanti Avalanche <6.4.7 - Path Traversal
CVSS 7.3
CVE-2024-55591 CRITICAL KEV
FortiProxy 7.0.0-7.0.19 and 7.2.0-7.2.12 - Authentication Bypass via Node.js Websocket Module
CVSS 9.8
CVE-2024-12402 CRITICAL
Themes Coder - Privilege Escalation
CVSS 9.8
CVE-2024-56044 CRITICAL
VibeThemes WPLMS < 1.9.9 - Unauthenticated Authentication Bypass via Alternate Path
CVSS 9.8
CVE-2024-51464 MEDIUM
IBM i 7.3-7.5 - Authenticated Authentication Bypass via Navigator for i Interface
CVSS 4.3
CVE-2024-11349 CRITICAL
AdForest theme <5.1.6 - Auth Bypass
CVSS 9.8
CVE-2024-43234 CRITICAL
Woffice < 5.4.14 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2024-56013 HIGH
Wovax IDX <= 1.2.2 - Authentication Bypass
CVSS 8.8
CVE-2024-54336 HIGH
Projectopia <= 5.1.7 - Authentication Bypass via Alternate Path
CVSS 8.8
CVE-2024-54297 CRITICAL
www.vbsso.com vBSSO-lite - Auth Bypass
CVSS 9.8
CVE-2024-54296 CRITICAL
CoSchool LMS <= 1.4.3 - Authentication Bypass
CVSS 9.8
CVE-2024-54295 CRITICAL
InspireUI ListApp Mobile Manager <1.7.7 - Auth Bypass
CVSS 9.8
CVE-2024-54294 CRITICAL
appgenixinfotech Firebase OTP Auth <1.0.1 - Auth Bypass
CVSS 9.8
CVE-2024-11639 CRITICAL
Ivanti Cloud Services Appliance < 5.0.3 - Unauthenticated Authentication Bypass in Admin Web Console
CVSS 10.0
CVE-2024-52586 MEDIUM
elabftw 4.6.0-5.1.8 - Multifactor Authentication Bypass via Local Authentication
CVSS 5.4
CVE-2024-11178 HIGH
Login With OTP plugin <1.4.2 - Auth Bypass
CVSS 8.1
CVE-2024-25036 MEDIUM
IBM Cognos Controller <11.0.1 - Auth Bypass
CVSS 4.3
CVE-2024-10490 HIGH
B&R mapp Services <6.0 - Auth Bypass
CVE-2024-11981 HIGH
Billion Electric Router - Auth Bypass
CVSS 7.5
CVE-2024-52475 CRITICAL
Wawp < 3.0.18 - Authentication Bypass
CVSS 9.8
CVE-2024-11925 CRITICAL
JobSearch WP Job Board <2.6.7 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 612