CWE-807

High likelihood

Reliance on Untrusted Inputs in a Security Decision

Parent: CWE-693 - Protection Mechanism Failure

The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

85 vulnerabilities with CWE-807
CVE-2026-32898 MEDIUM
OpenClaw < 2026.2.23 - ACP Permission Auto-Approval Bypass via Untrusted Tool Metadata
CVSS 5.4
CVE-2026-32057 HIGH
OpenClaw < 2026.2.25 - Authentication Bypass via Control UI client.id Parameter
CVSS 7.1
CVE-2026-29794 MEDIUM
Vikunja has Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
CVSS 5.3
CVE-2026-33068 HIGH
Claude Code <2.1.53 Repo Settings - Workspace Trust Bypass
CVSS 8.8
CVE-2026-31892 HIGH
Argo Workflows 2.9.0-4.0.1/3.7.0-3.7.10 - Auth Bypass
CVSS 8.1
CVE-2026-27707 HIGH
Seerr 2.0.0-3.0.9 - Unauthenticated Account Registration via Jellyfin Authentication Bypass
CVSS 7.3
CVE-2026-21514 HIGH KEV
Microsoft Office Word - Info Disclosure
CVSS 7.8
CVE-2026-25958 HIGH
Cube.js server-core 0.27.19-1.0.14 - Privilege Escalation via API Token
CVSS 7.7
CVE-2026-25931 HIGH
vscode-spell-checker <4.5.4 - Info Disclosure
CVSS 7.8
CVE-2026-21509 HIGH KEV
Microsoft 365 Apps and Office - Security Feature Bypass via Untrusted Input
CVSS 7.8
CVE-2026-23848 MEDIUM
MyTube < 1.7.71 - Unauthenticated Rate Limit Bypass via X-Forwarded-For Header Spoofing
CVSS 6.5
CVE-2026-20849 HIGH
Windows Kerberos - Privilege Escalation
CVSS 7.5
CVE-2025-13926 CRITICAL
Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision
CVSS 9.8
CVE-2025-65328 MEDIUM
mega-fence < 25.1.914 - IP Spoofing via X-Forwarded-For Header
CVSS 6.5
CVE-2025-66507 HIGH
1Panel < 2.0.14 - Unauthenticated CAPTCHA Bypass via Client-Controlled Parameter
CVSS 7.5
CVE-2025-66577 MEDIUM
cpp-httplib <0.27.0 - Log Poisoning
CVSS 5.3
CVE-2025-66570 CRITICAL
cpp-httplib <0.27.0 - Info Disclosure
CVSS 10.0
CVE-2025-10161 HIGH
Turkguven Software Technologies Inc. Perfektive <12574.2701 - Auth ...
CVSS 7.3
CVE-2025-12488 CRITICAL
oobabooga text-generation-webui - RCE
CVSS 9.8
CVE-2025-12487 CRITICAL
oobabooga text-generation-webui - RCE
CVSS 9.8
CVE-2025-11271 MEDIUM
Easy Digital Downloads <3.5.2 - Order Manipulation
CVSS 5.3
CVE-2025-53717 HIGH
Windows VBS Enclave - Privilege Escalation
CVSS 7.0
CVE-2025-59152 HIGH
Litestar 2.17.0 - Rate Limit Bypass via X-Forwarded-For Header Manipulation
CVSS 7.5
CVE-2025-55736 MEDIUM
flaskBlog <2.8.0 - Privilege Escalation
CVSS 6.5
CVE-2025-55735 MEDIUM
FlaskBlog < 2.8.0 - Stored Cross-Site Scripting via Post Content
CVSS 5.4
Details
Vulnerabilities 85
Exploit Likelihood High