CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,573 vulnerabilities with CWE-639
CVE-2025-13389 MEDIUM
WooCommerce: OrderConvo <14 - Info Disclosure
CVSS 5.3
CVE-2025-13382 MEDIUM
Frontend File Manager Plugin <23.4 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-12040 MEDIUM
WooCommerce Wishlist <1.0.9 - Insecure Direct Object Reference
CVSS 6.5
CVE-2025-10039 MEDIUM
Elula Wsdesk < 3.3.0 - IDOR
CVSS 4.3
CVE-2025-12881 MEDIUM
WooCommerce <4.5.5 - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-12086 MEDIUM
Return Refund & Exchange For WooCommerce <4.5.5 - Insecure Direct O...
CVSS 4.3
CVE-2025-52670 MEDIUM
Revive-adserver Revive Adserver < 5.5.2 - Missing Authorization
CVSS 6.5
CVE-2025-65034 HIGH
Rallly < 4.5.4 - IDOR
CVSS 8.1
CVE-2025-65033 HIGH
Rallly < 4.5.4 - Improper Authorization
CVSS 8.1
CVE-2025-65032 MEDIUM
Rallly < 4.5.4 - IDOR
CVSS 6.5
CVE-2025-65031 MEDIUM
Rallly < 4.5.4 - Improper Authorization
CVSS 6.5
CVE-2025-65030 HIGH
Rallly < 4.5.4 - Improper Authorization
CVSS 7.1
CVE-2025-65029 HIGH
Rallly < 4.5.4 - Missing Authorization
CVSS 8.1
CVE-2025-65028 MEDIUM
Rallly < 4.5.4 - Missing Authorization
CVSS 6.5
CVE-2025-65021 CRITICAL
Rallly < 4.5.4 - Missing Authorization
CVSS 9.1
CVE-2025-65020 MEDIUM
Rallly < 4.5.4 - Missing Authorization
CVSS 6.5
CVE-2025-12766 MEDIUM
BlackBerry AtHoc OnPrem <7.21 - Info Disclosure
CVSS 5.0
CVE-2025-12427 MEDIUM
YITH WooCommerce Wishlist <4.10.0 - Info Disclosure
CVSS 5.3
CVE-2025-63513 MEDIUM
kishan0725 Hospital Management System v4 - Info Disclosure
CVSS 6.5
CVE-2025-12524 MEDIUM
Post Type Switcher <4.0.0 - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-63291 MEDIUM
Alteryx Server 2022.1.1.42654-2024.1 - Info Disclosure
CVSS 5.4
CVE-2025-8855 HIGH
Optimus Software Brokerage Automation <1.1.71 - Auth Bypass
CVSS 8.1
CVE-2025-64706 MEDIUM
Typebot < 3.13.0 - Improper Access Control
CVSS 5.0
CVE-2025-41069 MEDIUM
T-INNOVA DeporSite - IDOR
CVE-2025-12366 MEDIUM
Pagelayer <2.0.5 - Insecure Direct Object Reference
CVSS 4.3
Details
Vulnerabilities 1,573
Exploit Likelihood High