CWE-472

External Control of Assumed-Immutable Web Parameter

Parent: CWE-642 - External Control of Critical State Data

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

140 vulnerabilities with CWE-472
CVE-2026-1982 MEDIUM
Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget
CVSS 5.3
CVE-2026-7484 MEDIUM
Improper Access Control in Abis Technology's AVESİS
CVSS 5.3
CVE-2026-65052 HIGH
Ninja Forms Calculation and Payment Total Tampering via Fail-Open get_calc_value in ListSelect and ListRadio Fields
CVSS 7.5
CVE-2026-56877 MEDIUM
Skillable Scorm Lab Launch Integration < 2026-07-13 - External Control of Assumed-Immutable Web Parameter
CVSS 6.3
CVE-2026-59817 MEDIUM
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
CVSS 5.3
CVE-2026-14430 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-14391 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.3
CVE-2026-14389 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-14387 CRITICAL
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 9.6
CVE-2026-14069 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 6.5
CVE-2026-13974 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.1
CVE-2026-13938 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-13841 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-13801 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-13796 CRITICAL
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 9.6
CVE-2026-13281 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-42655 MEDIUM
WordPress Best Payments Plugin for WP plugin <= 4.6.19 - Payment Bypass vulnerability
CVSS 5.9
CVE-2026-11678 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.3
CVE-2026-11669 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.3
CVE-2026-11655 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-11640 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-11290 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.0
CVE-2026-11281 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 5.0
CVE-2026-11211 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-11171 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
Details
Vulnerabilities 140