CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,573 vulnerabilities with CWE-639
CVE-2025-64523 HIGH
Filebrowser < 2.45.1 - Improper Authorization
CVSS 8.8
CVE-2025-12903 HIGH
Braintree For WooCommerce <3.2.78 - Auth Bypass
CVSS 7.5
CVE-2025-12833 MEDIUM
GeoDirectory - WP Business Directory Plugin <2.8.139 - Insecure Dir...
CVSS 4.3
CVE-2025-12087 MEDIUM
Woocommerce plugin <1.1.22 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-12126 MEDIUM
The Total Book Project plugin - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-11532 MEDIUM
Wisly plugin - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-12919 LOW
EverShop <2.0.1 - Info Disclosure
CVSS 3.7
CVE-2025-12918 LOW
yungifez Skuul School Management System <2.6.5 - Info Disclosure
CVSS 3.1
CVE-2025-12353 MEDIUM
WPFunnels <3.6.2 - Unauthorized Registration
CVSS 5.3
CVE-2025-11748 MEDIUM
Groups plugin for WordPress <3.7.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-64431 HIGH
Zitadel < 4.6.3 - IDOR
CVE-2025-12854 LOW
newbee-mall-plus <2.4.1 - Auth Bypass
CVSS 3.7
CVE-2025-58627 CRITICAL
Miraculous Core Plugin < 2.0.9 - Auth Bypass
CVSS 9.8
CVE-2025-63248 HIGH
DWSurvey 6.14.0 - Privilege Escalation
CVSS 7.5
CVE-2025-11690 HIGH
VehicleId IDOR - Info Disclosure
CVSS 8.5
CVE-2025-0987 CRITICAL
CB Project Ltd. Co. CVLand <20251103 - Auth Bypass
CVSS 9.9
CVE-2025-12623 LOW
fushengqian fuint <41e26be8a2c609413a0feaa69bdad33a71ae8032 - Auth ...
CVSS 3.1
CVE-2025-6574 HIGH
Service Finder Bookings <6.1 - Privilege Escalation
CVSS 8.8
CVE-2025-5949 HIGH
Service Finder Bookings <6.0 - Privilege Escalation
CVSS 8.8
CVE-2025-61876 MEDIUM
Inforcer Platform <2.0.153 - Info Disclosure
CVSS 5.0
CVE-2025-64283 MEDIUM
Rometheme RTMKit <1.6.7 - Auth Bypass
CVSS 6.5
CVE-2025-12351 MEDIUM
Honeywell S35 Series Cameras - Privilege Escalation
CVSS 6.8
CVE-2025-12288 MEDIUM
Bdtask Pharmacare < 9.4 - Improper Authorization
CVSS 4.3
CVE-2025-12283 MEDIUM
Fabian Client Details System - Improper Authorization
CVSS 4.3
CVE-2025-12270 MEDIUM
LearnHouse <98dfad76aad70711a8113f6c1fdabfccf10509ca - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 1,573
Exploit Likelihood High