CWE-472

External Control of Assumed-Immutable Web Parameter

Parent: CWE-642 - External Control of Critical State Data

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

140 vulnerabilities with CWE-472
CVE-2026-8567 MEDIUM
Google Chrome < 148.0.7778.168 - Integer Overflow in ANGLE via Crafted HTML Page
CVSS 4.3
CVE-2026-8559 MEDIUM
Google Chrome < 148.0.7778.168 - Integer Overflow in Internationalization via Crafted HTML Page
CVSS 4.3
CVE-2026-8534 HIGH
Google Chrome < 148.0.7778.168 - Sandbox Escape via GPU Integer Overflow
CVSS 8.3
CVE-2026-8532 HIGH
Google Chrome < 148.0.7778.168 - Remote Code Execution via Integer Overflow in XML
CVSS 8.8
CVE-2026-8519 HIGH
Google Chrome < 148.0.7778.168 - Integer Overflow in ANGLE via Crafted HTML Page
CVSS 8.8
CVE-2026-8510 HIGH
Google Chrome < 148.0.7778.168 - Integer Overflow in Skia via Crafted HTML Page
CVSS 7.5
CVE-2026-7973 HIGH
Google Chrome < 148.0.7778.96 - Integer Overflow in Dawn
CVSS 8.8
CVE-2026-7969 MEDIUM
Google Chrome < 148.0.7778.96 - Same Origin Policy Bypass via Integer Overflow in Network
CVSS 4.3
CVE-2026-7942 MEDIUM
Google Chrome < 148.0.7778.96 - Integer Overflow in ANGLE
CVSS 4.3
CVE-2026-7912 MEDIUM
Google Chrome < 148.0.7778.96 - Integer Overflow in GPU
CVSS 4.2
CVE-2026-7903 HIGH
Google Chrome < 148.0.7778.96 - Integer Overflow in ANGLE via Crafted HTML Page
CVSS 8.8
CVE-2026-7896 HIGH
Google Chrome < 148.0.7778.96 - Remote Code Execution via Integer Overflow in Blink
CVSS 8.8
CVE-2026-32699 MEDIUM
FacturaScripts unauthorized modification of immutable nick field via EditUser controller
CVE-2026-7340 MEDIUM
Google Chrome < 147.0.7727.138 - Integer Overflow in ANGLE via Crafted HTML Page
CVSS 4.3
CVE-2026-4911 MEDIUM
Booking Package <= 1.7.06 - Unauthenticated Price Manipulation via 'amount' Parameter
CVSS 5.3
CVE-2026-41353 HIGH
OpenClaw < 2026.3.22 - allowProfiles Bypass via Profile Mutation and Runtime Selection
CVSS 8.1
CVE-2026-2519 MEDIUM
Online Scheduling and Appointment Booking System – Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips'
CVSS 5.3
CVE-2026-5912 HIGH
Google Chrome < 147.0.7727.55 - Integer Overflow in WebRTC via Crafted HTML Page
CVSS 8.8
CVE-2026-5910 HIGH
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 8.8
CVE-2026-5909 HIGH
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 8.8
CVE-2026-5908 HIGH
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 8.8
CVE-2026-5870 HIGH
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 8.8
CVE-2026-5859 HIGH
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 8.8
CVE-2026-39364 HIGH
Vite Dev Server server.fs.deny - File Access Bypass
CVSS 7.5
CVE-2026-34751 CRITICAL
Payload has Unvalidated Input in Password Recovery Endpoints
CVSS 9.1
Details
Vulnerabilities 140