CWE-639
High likelihoodAuthorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
1,570 vulnerabilities with CWE-639
CVE-2026-3568
MEDIUM
MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update
CVSS 4.3
CVE-2026-2104
MEDIUM
Authorization Bypass Through User-Controlled Key in GitLab
CVSS 4.3
CVE-2026-5875
MEDIUM
Google Chrome <147.0.7727.55 - UI Spoofing
CVSS 4.3
CVE-2026-35478
HIGH
InvenTree has Arbitrary API Token Creation
CVSS 8.3
CVE-2026-35165
MEDIUM
LORIS has incorrect access checks in document_repository
CVSS 6.3
CVE-2026-34985
MEDIUM
LORIS has incorrect access checks in media module
CVSS 6.3
CVE-2026-32589
HIGH
Mirror-registry: quay: insecure direct object reference in blobupload
CVSS 7.4
CVE-2026-35023
MEDIUM
Wimi Teamwork On-Premises < 8.2.0 IDOR via preview.php
CVSS 4.3
CVE-2026-39616
MEDIUM
WordPress Download Attachments plugin <= 1.4.0 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.3
CVE-2026-39526
MEDIUM
WordPress WpStream plugin < 4.11.2 - Insecure Direct Object References (IDOR) vulnerability
CVSS 5.4
CVE-2026-39510
LOW
WordPress Image Photo Gallery Final Tiles Grid plugin <= 3.6.11 - Insecure Direct Object References (IDOR) vulnerability
CVSS 2.7
CVE-2026-4654
MEDIUM
Awesome Support <= 6.3.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter
CVSS 5.3
CVE-2026-4330
MEDIUM
Blog2Social: Social Media Auto Post & Scheduler < 8.8.3 - Authorization Bypass
CVSS 4.3
CVE-2026-5167
MEDIUM
Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint
CVSS 5.3
CVE-2026-39374
MEDIUM
Plane IDOR: Cross-Project Issue Date Modification via Bulk Update Endpoint
CVSS 6.5
CVE-2026-39354
MEDIUM
Scoold has an Authenticated Arbitrary Question Overwrite via Client-Controlled postId in POST /questions/ask
CVSS 6.5
CVE-2026-39331
HIGH
ChurchCRM has an API Authorization Bypass Allows Authenticated User to Deactivate, Modify, and Spam Arbitrary Families
CVSS 8.1
CVE-2026-39384
HIGH
FreeScout Customer Merge Cross-Mailbox Authorization Bypass
CVSS 7.6
CVE-2026-35584
MEDIUM
FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and Enumeration
CVSS 6.5
CVE-2026-35489
HIGH
Tandoor Recipes — `amount`/`unit` bypass serializer in `food/{id}/shopping/`
CVSS 7.3
CVE-2026-5465
HIGH
Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter
CVSS 8.8
CVE-2026-35183
HIGH
Brave CMS has an Insecure Direct Object Reference in Article Image Deletion
CVSS 7.1
CVE-2026-35173
MEDIUM
Chyrp Lite has an IDOR via Mass Assignment in Post Model
CVSS 6.5
CVE-2026-35045
HIGH
Tandoor Recipes Affected by Private Recipe Exposure and Unauthorized Modification
CVSS 8.1
CVE-2026-34444
HIGH
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
Details
Vulnerabilities
1,570
Exploit Likelihood
High