CWE-472

External Control of Assumed-Immutable Web Parameter

Parent: CWE-642 - External Control of Critical State Data

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

75 vulnerabilities with CWE-472
CVE-2025-10891 HIGH
Google Chrome <140.0.7339.207 - Heap Corruption
CVSS 8.8
CVE-2025-54551 MEDIUM
Synapse Mobility <8.2 - Privilege Escalation
CVSS 4.3
CVE-2025-54832 MEDIUM
OPEXUS FOIAXpress PAL <v11.1.0 - Privilege Escalation
CVSS 4.3
CVE-2025-8198 HIGH
MinimogWP - Price Manipulation
CVSS 7.5
CVE-2025-7656 HIGH
Google Chrome <138.0.7204.157 - Heap Corruption
CVSS 8.8
CVE-2025-43933 CRITICAL
fblog <983bede - Info Disclosure
CVSS 9.8
CVE-2025-43930 CRITICAL
Hashview 0.8.1 - Info Disclosure
CVSS 9.8
CVE-2025-6191 HIGH
Google Chrome < 137.0.7151.119 - Integer Overflow
CVSS 8.8
CVE-2025-43002 MEDIUM
SAP S4CORE - Info Disclosure
CVSS 4.3
CVE-2025-47817 HIGH
BlueWave Checkmate <2.0.2 - Privilege Escalation
CVSS 8.8
CVE-2025-35939 MEDIUM KEV
Craft CMS - RCE
CVSS 5.3
CVE-2025-47245 HIGH
BlueWave Checkmate <2.0.2 - Privilege Escalation
CVSS 8.1
CVE-2025-3743 MEDIUM
Upsell Funnel Builder <3.0.0 - Info Disclosure
CVSS 5.3
CVE-2025-3530 HIGH
WordPress Simple Shopping Cart <5.1.2 - Info Disclosure
CVSS 7.5
CVE-2025-31327 MEDIUM
SAP Field Logistics - Data Tampering
CVSS 4.3
CVE-2025-32816 LOW
CodeLit CourseLit <0.57.5 - Info Disclosure
CVSS 3.1
CVE-2025-31333 MEDIUM
SAP S4CORE - Info Disclosure
CVSS 4.3
CVE-2025-30152 MEDIUM
Sylius PayPal Plugin <2.0.2 - Info Disclosure
CVSS 6.5
CVE-2025-30236 HIGH
Shearwater SecurEnvoy SecurAccess <9.4.515 - Auth Bypass
CVSS 8.6
CVE-2025-29788 MEDIUM
Syliud PayPal Plugin <2.0.1 - Info Disclosure
CVSS 6.5
CVE-2025-26312 MEDIUM
SendQuick Entera <11HF5 - Auth Bypass
CVE-2025-27893 LOW
Archer Platform <6.14.00202.10024 - Privilege Escalation
CVSS 1.8
CVE-2025-25382 HIGH
Information Kerala Mission SANCHAYA <3.0.4 - Info Disclosure
CVSS 7.5
CVE-2025-0436 HIGH
Google Chrome <132.0.6834.83 - Heap Corruption
CVSS 8.8
CVE-2025-22384 HIGH
Optimizely Configured Commerce <5.2.2408 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 75