CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,779 vulnerabilities with CWE-639
CVE-2025-13822 MEDIUM
Authentication bypass in MCPHub
CVSS 5.3
CVE-2025-14974 MEDIUM
IBM InfoSphere Information Server is vulnerable due to Insecure Direct Object Reference
CVSS 5.7
CVE-2025-69347 HIGH
WordPress WPSubscription plugin <= 1.8.10 - Insecure Direct Object References (IDOR) vulnerability
CVSS 8.6
CVE-2025-32223 MEDIUM
WordPress Tutor LMS plugin <= 3.9.4 - Insecure Direct Object References (IDOR) vulnerability
CVSS 6.5
CVE-2025-69727 MEDIUM
INDEX-EDUCATION PRONOTE <2025.2.8 - Info Disclosure
CVSS 5.3
CVE-2025-67298 HIGH
ClasroomIO <0.2.6 - Privilege Escalation
CVSS 8.1
CVE-2025-62166 HIGH
FreshRSS < 1.28.0 - Authorization Bypass via Master Authentication Token
CVSS 7.5
CVE-2025-58402 HIGH
CGM CLININET < 2025.ms4 - Unauthenticated Authorization Bypass via MessageID Parameter
CVSS 7.5
CVE-2025-14742 MEDIUM
WP Recipe Maker <=10.2.3 - Info Disclosure
CVSS 4.3
CVE-2025-40541 CRITICAL
SolarWinds Serv-U < 15.5.4 - Authenticated Insecure Direct Object Reference
CVSS 9.1
CVE-2025-70833 CRITICAL
Smanga 3.2.7 - Unauthenticated Authentication Bypass via Password Reset Parameter Manipulation
CVSS 9.4
CVE-2025-15582 MEDIUM
detronetdip E-commerce 1.0.0 - Auth Bypass
CVSS 5.4
CVE-2025-69394 HIGH
Cnvrse <=026.02.10.20 - Auth Bypass
CVSS 7.5
CVE-2025-68514 MEDIUM
Paid Member Subscriptions <=2.16.8 - Auth Bypass
CVSS 6.5
CVE-2025-68051 HIGH
Shiprocket <= 2.0.8 - Authorization Bypass Through User-Controlled Key
CVSS 7.5
CVE-2025-9062 HIGH
Envanty < 1.0.6 - Authorization Bypass via Parameter Injection
CVSS 7.3
CVE-2025-13842 MEDIUM
Breadcrumb NavXT <=7.5.0 - Auth Bypass
CVSS 5.3
CVE-2025-70063 MEDIUM
PHPGurukul Hospital Management System 4.0 - Authorization Bypass via Medical History ViewID Parameter
CVSS 6.5
CVE-2025-12071 MEDIUM
WordPress Frontend User Notes <=2.1.0 - IDOR
CVSS 4.3
CVE-2025-69752 MEDIUM
Ideagen Q-Pulse 7.1.0.32 - Info Disclosure
CVSS 4.3
CVE-2025-13004 MEDIUM
Farktor Software E-Commerce Services Inc. E-Commerce Package <2.711...
CVSS 6.3
CVE-2025-14594 LOW
GitLab CE/EE <18.6.6-18.8.4 - Info Disclosure
CVSS 3.5
CVE-2025-15096 HIGH
Videospirecore Theme Plugin <1.0.6 - Privilege Escalation
CVSS 8.8
CVE-2025-10912 MEDIUM
Saastech TemizlikYolda <11022026 - Auth Bypass
CVSS 5.4
CVE-2025-7347 HIGH
Dinibh Patrol Tracking System <10022026 - Auth Bypass
CVSS 8.8
Details
Vulnerabilities 1,779
Exploit Likelihood High