CWE-345

Insufficient Verification of Data Authenticity

Parent: CWE-693 - Protection Mechanism Failure

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

657 vulnerabilities with CWE-345
CVE-2026-9242 MEDIUM
RegistrationMagic <= 6.0.8.6 - Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request
CVSS 5.3
CVE-2026-55698 HIGH
pnpm < 10.34.2 and 11.0.0-11.5.2 - Lockfile-Selected Code Execution
CVSS 8.8
CVE-2026-50573 MEDIUM
pnpm: Unsafe default behavior breaks integrity check
CVSS 6.8
CVE-2026-52812 HIGH
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-45792 MEDIUM
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
CVSS 5.5
CVE-2026-47155 MEDIUM
vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors
CVSS 6.5
CVE-2026-54288 MEDIUM
Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
CVSS 6.5
CVE-2026-54266 MEDIUM
Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
CVSS 6.1
CVE-2026-56073 CRITICAL
Cap-go - OTP Bypass via Response Manipulation in Email Verification
CVSS 9.4
CVE-2026-44087 CRITICAL
Apache APISIX: Openid-connect plugin Identity Header Spoofing
CVSS 9.1
CVE-2026-48783 MEDIUM
Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription
CVSS 4.8
CVE-2026-48781 CRITICAL
Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
CVSS 9.9
CVE-2026-53862 MEDIUM
OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening
CVSS 4.2
CVE-2026-53900 MEDIUM
Cookie injection was possible when opening a PDF link
CVSS 4.3
CVE-2026-53899 MEDIUM
Cross-origin cookies could be leaked when opening a PDF link
CVSS 6.5
CVE-2026-47777 HIGH
Mastodon has a consent-check bypass in its remote Collections
CVSS 7.5
CVE-2026-53406 HIGH
Zoom Communications Remote Control For Zoom Contact Center < 7.0.0 - Insufficient Verification of Data Authenticity
CVSS 7.8
CVE-2026-47691 HIGH
Netty has Insufficient Bailiwick Validation for NS Records
CVSS 8.7
CVE-2026-45674 HIGH
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
CVSS 8.7
CVE-2026-46654 HIGH
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
CVE-2026-48096 MEDIUM
OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning
CVSS 5.0
CVE-2026-46539 MEDIUM
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
CVSS 5.9
CVE-2026-7792 MEDIUM
WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint
CVSS 5.3
CVE-2026-8608 MEDIUM
Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action
CVSS 5.3
CVE-2026-50214 CRITICAL
Acer Connect M6E 5G Portable WiFi Router - Shared Secret Quota Inflation
CVSS 9.8
Details
Vulnerabilities 657