CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,796 vulnerabilities with CWE-639
CVE-2025-27561 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Room Rename
CVSS 5.3
CVE-2025-26857 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Device Rename
CVSS 5.3
CVE-2025-25276 MEDIUM
Growatt Cloud Portal <= 3.6.0 - Device Hijacking
CVSS 5.3
CVE-2025-24850 MEDIUM
Growatt Cloud Portal <= 3.6.0 - Information Disclosure
CVSS 5.3
CVE-2025-24315 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Device Addition
CVSS 5.3
CVE-2025-31949 MEDIUM
Growatt Cloud Portal < 3.6.0 - Authenticated Authorization Bypass via Plant ID
CVSS 5.3
CVE-2025-31941 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Username Enumeration
CVSS 5.3
CVE-2025-31933 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Username Enumeration via API Query
CVSS 5.3
CVE-2025-31357 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Authorization Bypass via Username
CVSS 5.3
CVE-2025-30514 MEDIUM
Smart Device Collections - Info Disclosure
CVSS 5.3
CVE-2025-30254 MEDIUM
Growatt Cloud Portal <= 3.6.0 - Information Disclosure
CVSS 5.3
CVE-2025-27939 HIGH
Growatt Cloud Portal < 3.6.0 - Unauthenticated Account Takeover via Email Change
CVSS 7.5
CVE-2025-27938 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Information Disclosure via User-Controlled Key
CVSS 5.3
CVE-2025-27568 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Email Disclosure via Password Reset Request
CVSS 5.3
CVE-2025-24487 MEDIUM
Growatt Cloud Portal < 3.6.0 - Unauthenticated Username Enumeration via API Query
CVSS 5.3
CVE-2025-3575 HIGH
Deporsite >= 05.29.0907 < 05.29.0907 - Insecure Direct Object Reference via idUsuario Parameter
CVE-2025-3574 HIGH
Deporsite >=v05.29.0907 <v05.29.0907 - Insecure Direct Object Reference via idUsuario Parameter
CVE-2025-3537 MEDIUM
Tutorials-Website Employee Management System 1.0 - Improper Authorization via ID Parameter in /admin/update-user.php
CVSS 5.3
CVE-2025-3536 MEDIUM
Tutorials-Website Employee Management System 1.0 - Improper Authorization in Delete User Function
CVSS 6.5
CVE-2025-3292 MEDIUM
WordPress <4.1.3 - Insecure Direct Object Reference
CVSS 4.3
CVE-2025-3282 MEDIUM
User Registration & Membership - Insecure Direct Object Reference
CVSS 5.3
CVE-2025-32373 MEDIUM
Dnnsoftware Dotnetnuke < 9.13.8 - IDOR
CVSS 6.5
CVE-2025-2526 HIGH
Streamit theme <4.0.2 - Privilege Escalation
CVSS 8.8
CVE-2025-22931 HIGH
OS4ED openSIS 7.0-9.1 - Unauthenticated Insecure Direct Object Reference in Staff Files Component
CVSS 7.5
CVE-2025-31867 MEDIUM
JoomSky JS Job Manager <2.0.2 - Auth Bypass
CVSS 5.4
Details
Vulnerabilities 1,796
Exploit Likelihood High