CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,573 vulnerabilities with CWE-639
CVE-2025-20214 MEDIUM
Cisco IOS XE - Info Disclosure
CVSS 4.3
CVE-2025-3853 MEDIUM
WPshop 2-2.6.0 - Insecure Direct Object Reference
CVSS 6.5
CVE-2025-3281 MEDIUM
WordPress <4.2.1 - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-3610 HIGH
Reales WP STPT <2.1.2 - Privilege Escalation
CVSS 8.8
CVE-2025-47226 MEDIUM
Grokability Snipe-IT <8.1.0 - Info Disclosure
CVSS 5.0
CVE-2025-4210 HIGH
Casdoor <1.811.0 - Auth Bypass
CVSS 7.3
CVE-2025-1327 MEDIUM
Favethemes Homey < 2.4.5 - IDOR
CVSS 4.3
CVE-2025-3889 MEDIUM
Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart < 5.1.4 - IDOR
CVSS 5.3
CVE-2025-3874 MEDIUM
Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart < 5.1.4 - IDOR
CVSS 6.5
CVE-2025-4119 MEDIUM
Weitong Mall - Improper Access Control
CVSS 5.3
CVE-2025-3640 MEDIUM
Moodle < 4.1.18 - IDOR
CVSS 4.3
CVE-2025-3636 MEDIUM
Moodle < 4.1.18 - IDOR
CVSS 4.3
CVE-2025-3625 HIGH
Moodle < 4.3.12 - IDOR
CVSS 7.1
CVE-2025-25777 HIGH
Codeastro Bus Ticket Booking System - IDOR
CVSS 8.0
CVE-2025-1284 MEDIUM
WooCommerce Automatic Order Printing <4.1 - Insecure Direct Object ...
CVSS 4.3
CVE-2025-42605 CRITICAL
Meon Bidding Solutions - Auth Bypass
CVE-2025-3519 HIGH
Unblu Spark - Auth Bypass
CVE-2025-39434 MEDIUM
Scott Taylor Avatar <0.1.4 - Auth Bypass
CVSS 4.3
CVE-2025-31950 MEDIUM
Growatt Cloud Portal < 3.6.0 - IDOR
CVSS 5.3
CVE-2025-31945 MEDIUM
Growatt Cloud Portal < 3.6.0 - IDOR
CVSS 5.3
CVE-2025-31654 MEDIUM
Growatt Cloud Portal <= 3.6.0 - Information Disclosure
CVSS 5.3
CVE-2025-31360 MEDIUM
Growatt Cloud Portal < 3.6.0 - IDOR
CVSS 6.5
CVE-2025-31147 MEDIUM
Growatt Cloud Portal < 3.6.0 - IDOR
CVSS 5.3
CVE-2025-30257 MEDIUM
Growatt Cloud Portal <= 3.6.0 - Information Disclosure
CVSS 5.3
CVE-2025-27929 MEDIUM
Growatt Cloud Portal < 3.6.0 - IDOR
CVSS 5.3
Details
Vulnerabilities 1,573
Exploit Likelihood High