CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,573 vulnerabilities with CWE-639
CVE-2025-58012 LOW
Alex Content Mask <1.8.5.2 - Auth Bypass
CVSS 3.8
CVE-2025-57994 MEDIUM
Sayful Islam Upcoming Events Lists <1.4.0 - Auth Bypass
CVSS 5.4
CVE-2025-0875 MEDIUM
PROLIZ OBS <v26.0328 - Auth Bypass
CVSS 6.5
CVE-2025-10759 MEDIUM
Webkul Qloapps < 1.7.0 - Improper Authorization
CVSS 5.3
CVE-2025-9081 LOW
Mattermost <10.5.8, <9.11.17 - Info Disclosure
CVSS 3.1
CVE-2025-43803 MEDIUM
Liferay Digital Experience Platform < 7.3 - IDOR
CVSS 4.3
CVE-2025-8532 MEDIUM
Bimser Solution Software Trade Inc. EBA Document and Workflow Manag...
CVSS 6.4
CVE-2025-10719 MEDIUM
Tronclass - Info Disclosure
CVSS 4.3
CVE-2025-5948 CRITICAL
Service Finder Bookings <6.0 - Privilege Escalation
CVSS 9.8
CVE-2025-10493 MEDIUM
Chained Quiz <1.3.4 - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-8463 MEDIUM
SecHard <3.6.2-20250805 - Auth Bypass
CVSS 5.3
CVE-2025-8057 MEDIUM
Patika Global Technologies HumanSuite <53.21.0 - Auth Bypass
CVSS 6.5
CVE-2025-7355 MEDIUM
Beefull App <24.07.2025 - Auth Bypass
CVSS 6.5
CVE-2025-5518 MEDIUM
ArgusTech BILGER <2.4.6 - Auth Bypass
CVSS 6.5
CVE-2025-43790 HIGH
Liferay Digital Experience Platform < 2024.Q1.13 - IDOR
CVSS 8.1
CVE-2025-43782 MEDIUM
Liferay Digital Experience Platform < 2024.Q1.13 - IDOR
CVSS 4.3
CVE-2025-59034 MEDIUM
Cern Indico < 3.3.8 - IDOR
CVSS 4.3
CVE-2025-7718 HIGH
Resideo Plugin <2.5.4 - Privilege Escalation
CVSS 8.8
CVE-2025-7049 HIGH
WPGYM - Privilege Escalation
CVSS 8.8
CVE-2025-52389 HIGH
Envasadora H2O Eireli - Soda Cristal v40.20.4 - Info Disclosure
CVSS 8.8
CVE-2025-9114 CRITICAL
Doccure theme <1.4.8 - Privilege Escalation
CVSS 9.8
CVE-2025-58597 MEDIUM
Tomdever wpForo Forum <2.4.6 - Auth Bypass
CVSS 4.3
CVE-2025-22422 HIGH
Google Android - IDOR
CVSS 7.8
CVE-2025-9836 MEDIUM
Macrozheng Mall < 1.0.3 - Improper Authorization
CVSS 4.3
CVE-2025-9835 MEDIUM
Macrozheng Mall < 1.0.3 - Incorrect Authorization
CVSS 4.3
Details
Vulnerabilities 1,573
Exploit Likelihood High