CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,796 vulnerabilities with CWE-639
CVE-2025-47226 MEDIUM
Grokability Snipe-IT <8.1.0 - Info Disclosure
CVSS 5.0
CVE-2025-4210 HIGH
Casdoor < 1.812.0 - Authorization Bypass via SCIM User Creation Endpoint
CVSS 7.3
CVE-2025-1327 MEDIUM
Homey < 2.4.4 - Authenticated Insecure Direct Object Reference via homey_delete_user_account Action
CVSS 4.3
CVE-2025-3889 MEDIUM
WordPress Simple Shopping Cart <= 5.1.3 - Unauthenticated Insecure Direct Object Reference via process_payment_data
CVSS 5.3
CVE-2025-3874 MEDIUM
WordPress Simple Shopping Cart <= 5.1.3 - Unauthenticated Insecure Direct Object Reference via User-Controlled Key
CVSS 6.5
CVE-2025-4119 MEDIUM
Weitong Mall 1.0.0 - Improper Access Control in Product Statistics Handler
CVSS 5.3
CVE-2025-3640 MEDIUM
Moodle < 4.1.18 - Authorization Bypass via Insufficient Capability Checks
CVSS 4.3
CVE-2025-3636 MEDIUM
Moodle < 4.1.18 - Authorization Bypass via RSS Feed Access
CVSS 4.3
CVE-2025-3625 HIGH
Moodle 4.3.0-4.3.11 - Authorization Bypass via Two-Factor Authentication
CVSS 7.1
CVE-2025-25777 HIGH
Codeastro Bus Ticket Booking System 1.0 - Unauthenticated Insecure Direct Object Reference via User ID Parameter
CVSS 8.0
CVE-2025-1284 MEDIUM
WooCommerce Automatic Order Printing <4.1 - Insecure Direct Object ...
CVSS 4.3
CVE-2025-42605 CRITICAL
Meon Bidding Solutions - Auth Bypass
CVE-2025-3519 HIGH
Unblu Spark 8.0.0-8.12.1 and >=8.13.1 - Authorization Bypass via File ID Reuse
CVE-2025-39434 MEDIUM
Scott Taylor Avatar <0.1.4 - Auth Bypass
CVSS 4.3
CVE-2025-31950 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass
CVSS 5.3
CVE-2025-31945 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass
CVSS 5.3
CVE-2025-31654 MEDIUM
Growatt Cloud Portal <= 3.6.0 - Information Disclosure
CVSS 5.3
CVE-2025-31360 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Scene Device Actions
CVSS 6.5
CVE-2025-31147 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Information Disclosure via EV Charger Energy Query
CVSS 5.3
CVE-2025-30257 MEDIUM
Growatt Cloud Portal <= 3.6.0 - Information Disclosure
CVSS 5.3
CVE-2025-27929 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated User Enumeration
CVSS 5.3
CVE-2025-27927 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Device List Exposure via API
CVSS 5.3
CVE-2025-27719 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via API Endpoint
CVSS 5.3
CVE-2025-27575 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Information Disclosure via Charger ID
CVSS 5.3
CVE-2025-27565 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Room Deletion
CVSS 5.3
Details
Vulnerabilities 1,796
Exploit Likelihood High