CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
138 vulnerabilities with CWE-915
CVE-2026-34406
HIGH
APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpoint
CVSS 8.8
CVE-2026-33228
CRITICAL
flatted: Prototype Pollution via parse()
CVSS 9.8
CVE-2026-27953
HIGH
ormar <0.23.1 Model Constructor - Pydantic Validation Bypass
CVSS 7.1
CVE-2026-32742
MEDIUM
Parse Server session creation endpoint allows overwriting server-generated session fields
CVSS 4.3
CVE-2026-29056
HIGH
Kanboard's privilege escalation via mass assignment in user invite registration allows any invited user to become admin
CVSS 8.8
CVE-2026-21886
MEDIUM
OpenCTI's GraphQL Mutations Allow Deletion of Unrelated Entities
CVSS 6.5
CVE-2026-32640
CRITICAL
(SimpleEval) Objects (including modules) can leak dangerous modules through to direct access inside the sandbox.
CVSS 9.8
CVE-2026-27591
CRITICAL
Winter CMS <1.0.477/1.1.12/1.2.12 - Privilege Escalation
CVSS 9.9
CVE-2026-31815
MEDIUM
django-unicorn <0.67.0 - Auth Bypass
CVSS 5.3
CVE-2026-30822
HIGH
Flowise < 3.0.13 - Unauthenticated Arbitrary Database Field Injection via Lead Creation
CVSS 7.7
CVE-2026-29063
CRITICAL
Immutable.js <3.8.3/4.3.7/5.1.5 - Prototype Pollution
CVSS 9.8
CVE-2026-28781
MEDIUM
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Privilege Escalation
CVSS 6.5
CVE-2026-28219
MEDIUM
Discourse <2025.12.2/2026.1.1/2026.2.0 - Privilege Escalation
CVSS 4.3
CVE-2026-27125
MEDIUM
svelte < 5.51.5 - Prototype Pollution in Server-Side Rendering Attribute Spreading
CVSS 6.8
CVE-2026-25521
HIGH
locutus 2.0.12-2.0.38 - Prototype Pollution via String.prototype
CVSS 8.8
CVE-2026-24140
LOW
MyTube < 1.7.78 - Mass Assignment via Settings Management
CVSS 2.7
CVE-2026-23522
LOW
LobeChat <2.0.0-next.193 - Privilege Escalation
CVSS 3.7
CVE-2026-22814
HIGH
@adonisjs/lucid <22.0.0-next.6 - SQL Injection
CVE-2026-22783
CRITICAL
Iris <2.4.24 - Privilege Escalation
CVSS 9.6
CVE-2026-21695
MEDIUM
Titra < 0.99.50 - Authenticated Mass Assignment via Customfields Parameter
CVSS 4.3
CVE-2025-69691
CRITICAL
Netgate pfSense CE 2.8.0 - Code Injection
CVSS 9.9
CVE-2025-69690
CRITICAL
Netgate pfSense CE 2.7.2 - Code Injection
CVSS 9.1
CVE-2025-14341
HIGH
Input Data Manipulation in DivvyDrive Information Technologies' DivvyDrive
CVSS 8.3
CVE-2025-15602
HIGH
Snipe-IT <8.3.7 - Privilege Escalation
CVSS 8.8
CVE-2025-61781
HIGH
OpenCTI < 6.8.1 - Unauthenticated Authorization Bypass via WorkspacePopoverDeletionMutation
CVSS 7.1
Details
Vulnerabilities
138