CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,794 vulnerabilities with CWE-639
CVE-2025-52670 MEDIUM
Revive Adserver < 5.5.2 - Authorization Bypass via Banner Deletion
CVSS 6.5
CVE-2025-65034 HIGH
rallly < 4.5.4 - Authenticated Authorization Bypass via PollId Parameter
CVSS 8.1
CVE-2025-65033 HIGH
rallly < 4.5.4 - Authenticated Authorization Bypass in Poll Management
CVSS 8.1
CVE-2025-65032 MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via ParticipantId Parameter
CVSS 6.5
CVE-2025-65031 MEDIUM
rallly < 4.5.4 - Authenticated User Impersonation via Comment AuthorName Field
CVSS 6.5
CVE-2025-65030 HIGH
rallly < 4.5.4 - Authenticated Authorization Bypass via Comment Deletion API
CVSS 7.1
CVE-2025-65029 HIGH
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference in Participant Deletion Endpoint
CVSS 8.1
CVE-2025-65028 MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via ParticipantId Parameter
CVSS 6.5
CVE-2025-65021 CRITICAL
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Finalization
CVSS 9.1
CVE-2025-65020 MEDIUM
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Duplication Endpoint
CVSS 6.5
CVE-2025-12766 MEDIUM
BlackBerry AtHoc OnPrem <7.21 - Info Disclosure
CVSS 5.0
CVE-2025-12427 MEDIUM
YITH WooCommerce Wishlist <4.10.0 - Info Disclosure
CVSS 5.3
CVE-2025-63513 MEDIUM
kishan0725 Hospital Management System v4 - Info Disclosure
CVSS 6.5
CVE-2025-12524 MEDIUM
Post Type Switcher <4.0.0 - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-63291 MEDIUM
Alteryx Server 2022.1.1.42654-2024.1 - Info Disclosure
CVSS 5.4
CVE-2025-8855 HIGH
Optimus Software Brokerage Automation <1.1.71 - Auth Bypass
CVSS 8.1
CVE-2025-64706 MEDIUM
typebot 3.9.0-3.12.9 - Authenticated Insecure Direct Object Reference in API Token Management
CVSS 5.0
CVE-2025-41069 MEDIUM
T-Innova DeporSite DSuite 2025 >=v02.14.1115 <v02.14.1115 - Authorization Bypass via idUsuario Parameter
CVE-2025-12366 MEDIUM
Pagelayer <2.0.5 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-64523 HIGH
filebrowser < 2.45.1 - Authenticated Insecure Direct Object Reference in Share Deletion
CVSS 8.8
CVE-2025-12903 HIGH
Braintree For WooCommerce <3.2.78 - Auth Bypass
CVSS 7.5
CVE-2025-12833 MEDIUM
GeoDirectory - WP Business Directory Plugin <2.8.139 - Insecure Dir...
CVSS 4.3
CVE-2025-12087 MEDIUM
Woocommerce plugin <1.1.22 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-12126 MEDIUM
The Total Book Project plugin - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-11532 MEDIUM
Wisly plugin - Insecure Direct Object Reference
CVSS 5.3
Details
Vulnerabilities 1,794
Exploit Likelihood High