CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,573 vulnerabilities with CWE-639
CVE-2025-34293 HIGH
GN4 Publishing System <2.6 - Info Disclosure
CVE-2025-11957 HIGH
Devolutions Server < 2025.2.14.0 - IDOR
CVSS 8.4
CVE-2025-49952 MEDIUM
Houzez <4.1.1 - Auth Bypass
CVSS 6.5
CVE-2025-6833 MEDIUM
All in One Time Clock Lite - WordPress <2.0 - Insecure Direct Objec...
CVSS 4.3
CVE-2025-10570 MEDIUM
WooCommerce Flexible Refund Return Order <1.0.38 - Auth Bypass
CVSS 4.3
CVE-2025-60511 MEDIUM
Moodle OpenAI Chat Block plugin 3.0.1 - IDOR
CVSS 4.3
CVE-2025-8884 MEDIUM
VHS Electronic Software Ltd. Co. ACE Center <3.10.161.2255 - Privil...
CVSS 5.5
CVE-2025-11741 MEDIUM
WPC Smart Quick View <4.2.5 - Info Disclosure
CVSS 5.3
CVE-2025-11519 MEDIUM
Optimole <4.1.0 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-11517 HIGH
WordPress Event Tickets & Registration <5.26.5 - Auth Bypass
CVSS 7.5
CVE-2025-11895 MEDIUM
Binary MLM Plan <3.0 - Info Disclosure
CVSS 4.3
CVE-2025-9559 MEDIUM
Pega Platform <Infinity - Info Disclosure
CVSS 6.5
CVE-2025-41020 HIGH
Sergestec Exito - IDOR
CVSS 7.5
CVE-2025-10742 CRITICAL
Truelysell Core <1.8.6 - Privilege Escalation
CVSS 9.8
CVE-2025-11176 MEDIUM
Quick Featured Images <13.7.2 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-40773 LOW
Siemens Sipass Integrated < 3.00 - IDOR
CVSS 3.5
CVE-2025-62252 MEDIUM
Liferay Digital Experience Platform < 7.4 - IDOR
CVSS 4.3
CVE-2025-62242 MEDIUM
Liferay Digital Experience Platform < 7.4.3.112 - IDOR
CVSS 4.3
CVE-2025-62241 MEDIUM
Liferay Digital Experience Platform < 4.0.114 - IDOR
CVSS 4.3
CVE-2025-62244 MEDIUM
Liferay Digital Experience Platform < 2023.q3.9 - IDOR
CVSS 4.3
CVE-2025-9902 HIGH
AKIN Software Computer Import Export Industry and Trade Co. Ltd. QR...
CVSS 7.5
CVE-2025-31997 MEDIUM
Hcltech Unica Centralized Offer Management < 25.1.0.1 - IDOR
CVSS 4.2
CVE-2025-11518 MEDIUM
WPC Smart Wishlist <5.0.3 - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-8887 MEDIUM
Usta Information Systems Inc. Aybs Interaktif - Info Disclosure
CVSS 6.1
CVE-2025-61779 HIGH
Confidential Containers Trustee <0.15.0 - Auth Bypass
Details
Vulnerabilities 1,573
Exploit Likelihood High