CWE-472

External Control of Assumed-Immutable Web Parameter

Parent: CWE-642 - External Control of Critical State Data

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

140 vulnerabilities with CWE-472
CVE-2026-11088 CRITICAL
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 9.6
CVE-2026-11085 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-11058 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-11044 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 6.5
CVE-2026-10987 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10986 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10965 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10964 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10963 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10924 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-10921 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9998 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9968 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-9966 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.3
CVE-2026-9960 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-9911 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 4.3
CVE-2026-9909 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-9882 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 6.5
CVE-2026-10019 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10018 MEDIUM
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 6.5
CVE-2026-10015 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 8.8
CVE-2026-10009 HIGH
Google Chrome - External Control of Assumed-Immutable Web Parameter
CVSS 7.5
CVE-2026-7571 HIGH
Keycloak: keycloak: access token disclosure and implicit flow bypass via forged client data
CVSS 7.1
CVE-2026-8577 HIGH
Google Chrome < 148.0.7778.168 - Remote Code Execution via Integer Overflow in Fonts
CVSS 8.8
CVE-2026-8573 HIGH
Google Chrome < 148.0.7778.168 - Integer Overflow in Codecs via Crafted Video File
CVSS 8.3
Details
Vulnerabilities 140