CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,572 vulnerabilities with CWE-639
CVE-2025-67298 HIGH
ClasroomIO <0.2.6 - Privilege Escalation
CVSS 8.1
CVE-2025-62166 HIGH
FreshRSS <1.28.0 - Auth Bypass
CVSS 7.5
CVE-2025-58402 HIGH
CGM CLININET - Auth Bypass
CVSS 7.5
CVE-2025-14742 MEDIUM
WP Recipe Maker <=10.2.3 - Info Disclosure
CVSS 4.3
CVE-2025-40541 CRITICAL
Serv-U - Privilege Escalation
CVSS 9.1
CVE-2025-70833 CRITICAL
Smanga 3.2.7 - Auth Bypass
CVSS 9.4
CVE-2025-15582 MEDIUM
detronetdip E-commerce 1.0.0 - Auth Bypass
CVSS 5.4
CVE-2025-69394 HIGH
Cnvrse <=026.02.10.20 - Auth Bypass
CVSS 7.5
CVE-2025-68514 MEDIUM
Paid Member Subscriptions <=2.16.8 - Auth Bypass
CVSS 6.5
CVE-2025-68051 HIGH
Shiprocket <=2.0.8 - Auth Bypass
CVSS 7.5
CVE-2025-9062 HIGH
Envanty <1.0.6 - Auth Bypass
CVSS 7.3
CVE-2025-13842 MEDIUM
Breadcrumb NavXT <=7.5.0 - Auth Bypass
CVSS 5.3
CVE-2025-70063 MEDIUM
PHPGurukul HMS 4.0 - IDOR
CVSS 6.5
CVE-2025-12071 MEDIUM
WordPress Frontend User Notes <=2.1.0 - IDOR
CVSS 4.3
CVE-2025-69752 MEDIUM
Ideagen Q-Pulse 7.1.0.32 - Info Disclosure
CVSS 4.3
CVE-2025-13004 MEDIUM
Farktor Software E-Commerce Services Inc. E-Commerce Package <2.711...
CVSS 6.3
CVE-2025-14594 LOW
GitLab CE/EE <18.6.6-18.8.4 - Info Disclosure
CVSS 3.5
CVE-2025-15096 HIGH
Videospirecore Theme Plugin <1.0.6 - Privilege Escalation
CVSS 8.8
CVE-2025-10912 MEDIUM
Saastech TemizlikYolda <11022026 - Auth Bypass
CVSS 5.4
CVE-2025-7347 HIGH
Dinibh Patrol Tracking System <10022026 - Auth Bypass
CVSS 8.8
CVE-2025-12063 MEDIUM
Product <Version - Info Disclosure
CVSS 5.7
CVE-2025-15147 MEDIUM
WCFM Membership - WooCommerce Memberships <2.11.8 - Insecure Direct...
CVSS 4.3
CVE-2025-69207 MEDIUM
Pypi Khoj - IDOR
CVSS 5.4
CVE-2025-36365 MEDIUM
IBM Db2 < 11.5.9 - IDOR
CVSS 6.8
CVE-2025-7013 MEDIUM
QR Menu Pro Smart Menu Systems Menu Panel <29012026 - Auth Bypass
CVSS 5.7
Details
Vulnerabilities 1,572
Exploit Likelihood High