CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
138 vulnerabilities with CWE-915
CVE-2026-12436
HIGH
Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
CVSS 8.4
CVE-2026-63428
MEDIUM
HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field set
CVSS 5.8
CVE-2026-63102
MEDIUM
rConfig Core < 8.2.8 Privilege Escalation via Users API role field
CVSS 5.4
CVE-2026-56679
HIGH
9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
CVE-2026-59888
MEDIUM
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
CVSS 6.5
CVE-2026-58477
HIGH
Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters
CVSS 8.2
CVE-2026-55810
HIGH
Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050
CVSS 8.1
CVE-2026-55809
HIGH
Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049
CVSS 8.1
CVE-2026-55804
MEDIUM
Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
CVSS 5.9
CVE-2026-55803
MEDIUM
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
CVSS 5.9
CVE-2026-15083
MEDIUM
ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074
CVSS 4.2
CVE-2026-13244
HIGH
Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064
CVSS 8.1
CVE-2026-12535
CRITICAL
Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
CVSS 9.8
CVE-2026-9726
CRITICAL
Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038
CVSS 9.8
CVE-2026-59721
HIGH
Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
CVSS 7.2
CVE-2026-54601
MEDIUM
FastGPT < 4.15.0-beta4 - Cross-Tenant Dataset Authorization Bypass
CVSS 6.3
CVE-2026-43925
MEDIUM
FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use
CVE-2026-50281
HIGH
Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
CVE-2026-50160
CRITICAL
Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite
CVSS 10.0
CVE-2026-55223
MEDIUM
c3p0 exposes a deserialization "sink" via JDBC DataSource bean properties
CVE-2026-54351
HIGH
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
CVSS 8.2
CVE-2026-48943
MEDIUM
Joomla Extension - getk2.com - Authenticated user property mass-assignment in K2 extension for Joomla < 2.26
CVSS 6.5
CVE-2026-45687
HIGH
Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage
CVSS 8.5
CVE-2026-54516
MEDIUM
jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields
CVSS 5.3
CVE-2026-54515
MEDIUM
jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
CVSS 5.3
Details
Vulnerabilities
138