CWE-472
External Control of Assumed-Immutable Web Parameter
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.
123 vulnerabilities with CWE-472
CVE-2026-42655
MEDIUM
WordPress Best Payments Plugin for WP plugin <= 4.6.19 - Payment Bypass vulnerability
CVSS 5.9
CVE-2026-11678
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.3
CVE-2026-11669
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.3
CVE-2026-11655
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-11640
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-11290
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.0
CVE-2026-11281
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.0
CVE-2026-11211
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-11171
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-11088
CRITICAL
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 9.6
CVE-2026-11085
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-11058
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-11044
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 6.5
CVE-2026-10987
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10986
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10965
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10964
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10963
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10924
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-10921
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9998
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9968
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-9966
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9960
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-9911
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 4.3
Details
Vulnerabilities
123