CWE-472

External Control of Assumed-Immutable Web Parameter

Parent: CWE-642 - External Control of Critical State Data

The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.

140 vulnerabilities with CWE-472
CVE-2025-35939 MEDIUM KEV
Craft CMS < 4.15.3 and 5.0.0-alpha.1-5.7.5 - Unauthenticated Arbitrary File Write via Session File Injection
CVSS 5.3
CVE-2025-47245 HIGH
BlueWave Checkmate <2.0.2 - Privilege Escalation
CVSS 8.1
CVE-2025-3743 MEDIUM
Upsell Funnel Builder <3.0.0 - Info Disclosure
CVSS 5.3
CVE-2025-3530 HIGH
WordPress Simple Shopping Cart <5.1.2 - Info Disclosure
CVSS 7.5
CVE-2025-31327 MEDIUM
SAP Field Logistics - Data Tampering
CVSS 4.3
CVE-2025-32816 LOW
CodeLit CourseLit <0.57.5 - Info Disclosure
CVSS 3.1
CVE-2025-31333 MEDIUM
SAP S4CORE entity - Data Tampering via OData Meta-Data Property
CVSS 4.3
CVE-2025-30152 MEDIUM
Sylius PayPal Plugin <2.0.2 - Info Disclosure
CVSS 6.5
CVE-2025-30236 HIGH
Shearwater SecurEnvoy SecurAccess <9.4.515 - Auth Bypass
CVSS 8.6
CVE-2025-29788 MEDIUM
Syliud PayPal Plugin <2.0.1 - Info Disclosure
CVSS 6.5
CVE-2025-26312 MEDIUM
SendQuick Entera <11HF5 - Auth Bypass
CVE-2025-27893 LOW
Archer Platform <6.14.00202.10024 - Privilege Escalation
CVSS 1.8
CVE-2025-25382 HIGH
Information Kerala Mission SANCHAYA <3.0.4 - Info Disclosure
CVSS 7.5
CVE-2025-0436 HIGH
Google Chrome <132.0.6834.83 - Heap Corruption
CVSS 8.8
CVE-2025-22384 HIGH
Optimizely Configured Commerce <5.2.2408 - Info Disclosure
CVSS 7.5
CVE-2024-50703 MEDIUM
TeamPass <3.1.3.1 - Privilege Escalation
CVSS 5.4
CVE-2024-12123 MEDIUM
Issuetrak 17.1 - Authenticated User Impersonation via Hidden Field Manipulation
CVE-2024-7025 HIGH
Google Chrome < 129.0.6668.89 - Integer Overflow in Layout via Crafted HTML Page
CVSS 8.8
CVE-2024-9123 HIGH
Google Chrome < 129.0.6668.70 - Integer Overflow in Skia via Crafted HTML Page
CVSS 8.8
CVE-2024-6010 MEDIUM
Cost Calculator Builder PRO <3.2.1 - Info Disclosure
CVSS 5.3
CVE-2024-3649 MEDIUM
The Contact Form by WPForms - WordPress <1.8.7.2 - Info Disclosure
CVSS 5.3
CVE-2024-25153 CRITICAL
FileCatalyst Workflow Web Portal - Path Traversal
CVSS 9.8
CVE-2024-22049 MEDIUM
httparty <0.21.0 - Info Disclosure
CVSS 5.3
CVE-2023-38520 MEDIUM
PINPOINT.WORLD Pinpoint Booking System <2.9.9.3.4 - XSS
CVSS 6.5
CVE-2023-24373 LOW
WpDevArt Booking calendar <3.2.3 - XSS
CVSS 3.7
Details
Vulnerabilities 140