CWE-472
External Control of Assumed-Immutable Web Parameter
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.
140 vulnerabilities with CWE-472
CVE-2026-11088
CRITICAL
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 9.6
CVE-2026-11085
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-11058
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-11044
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 6.5
CVE-2026-10987
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10986
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10965
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10964
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10963
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10924
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-10921
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9998
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9968
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-9966
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9960
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-9911
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 4.3
CVE-2026-9909
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-9882
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 6.5
CVE-2026-10019
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10018
MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 6.5
CVE-2026-10015
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10009
HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-7571
HIGH
Keycloak: keycloak: access token disclosure and implicit flow bypass via forged client data
CVSS 7.1
CVE-2026-8577
HIGH
Google Chrome < 148.0.7778.168 - Remote Code Execution via Integer Overflow in Fonts
CVSS 8.8
CVE-2026-8573
HIGH
Google Chrome < 148.0.7778.168 - Integer Overflow in Codecs via Crafted Video File
CVSS 8.3
Details
Vulnerabilities
140