CWE-472

External Control of Assumed-Immutable Web Parameter

Parent: CWE-642 - External Control of Critical State Data

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

140 vulnerabilities with CWE-472
CVE-2026-5277 HIGH
Google Chrome < 146.0.7680.178 - Integer Overflow in ANGLE via Crafted HTML Page
CVSS 7.5
CVE-2026-5274 HIGH
Google Chrome <146.0.7680.178 - Memory Corruption
CVSS 8.8
CVE-2026-4679 HIGH
Google Chrome < 146.0.7680.165 - Integer Overflow in Fonts via Crafted HTML Page
CVSS 8.8
CVE-2026-4464 HIGH
Google Chrome <146.0.7680.153 - Memory Corruption
CVSS 8.8
CVE-2026-4453 MEDIUM
Google Chrome <146.0.7680.153 - Info Disclosure
CVSS 4.3
CVE-2026-4452 HIGH
Google Chrome <146.0.7680.153 - Memory Corruption
CVSS 8.8
CVE-2026-3914 HIGH
Google Chrome <146.0.7680.71 - Memory Corruption
CVSS 8.8
CVE-2026-3538 HIGH
Google Chrome <145.0.7632.159 - Memory Corruption
CVSS 8.8
CVE-2026-3536 HIGH
Google Chrome <145.0.7632.159 - Memory Corruption
CVSS 8.8
CVE-2026-2649 HIGH
Google Chrome <145.0.7632.109 - Memory Corruption
CVSS 8.8
CVE-2025-59382 LOW
QNAP Systems - QTS, QuTS Hero, QuTScloud, QVP (QVR Pro Appliances)
CVE-2025-14750 HIGH
Web App - Privilege Escalation
CVE-2025-67846 MEDIUM
Mintlify Platform <2025-11-15 - Auth Bypass
CVSS 4.9
CVE-2025-66385 CRITICAL
Cerebrate <1.30 - Privilege Escalation
CVE-2025-10892 HIGH
Google Chrome < 140.0.7339.207 - Integer Overflow in V8 via Crafted HTML Page
CVSS 8.8
CVE-2025-10891 HIGH
Google Chrome <140.0.7339.207 - Heap Corruption
CVSS 8.8
CVE-2025-54551 MEDIUM
Synapse Mobility <8.2 - Privilege Escalation
CVSS 4.3
CVE-2025-54832 MEDIUM
OPEXUS FOIAXpress PAL <v11.1.0 - Privilege Escalation
CVSS 4.3
CVE-2025-8198 HIGH
MinimogWP < 3.9.0 - Unauthenticated Price Manipulation via Cart Quantity Parameter
CVSS 7.5
CVE-2025-7656 HIGH
Google Chrome <138.0.7204.157 - Heap Corruption
CVSS 8.8
CVE-2025-43933 CRITICAL
fblog through 983bede - Account Takeover via Password Reset Host Header Manipulation
CVSS 9.8
CVE-2025-43930 CRITICAL
Hashview 0.8.1 - Account Takeover via Password Reset Host Header Manipulation
CVSS 9.8
CVE-2025-6191 HIGH
Google Chrome < 137.0.7151.119 - Integer Overflow in V8 via Crafted HTML Page
CVSS 8.8
CVE-2025-43002 MEDIUM
SAP S4/HANA OData Meta-Data Property - Authenticated Information Disclosure via Missing Authorization Check
CVSS 4.3
CVE-2025-47817 HIGH
BlueWave Checkmate <2.0.2 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 140