CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains

Parent: CWE-863 - Incorrect Authorization

The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.

84 vulnerabilities with CWE-942
CVE-2026-7581 MEDIUM
alexta69 MeTube CORS Policy main.py on_prepare cross-domain policy
CVSS 4.3
CVE-2026-41056 HIGH
AVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover
CVSS 8.1
CVE-2026-34839 MEDIUM
Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
CVSS 6.5
CVE-2026-6662 HIGH
ericc-ch copilot-api Token Endpoint server.ts cors cross-domain policy
CVSS 7.3
CVE-2026-6143 MEDIUM
farion1231 cc-switch ProxyServer server.rs cross-domain policy
CVSS 6.3
CVE-2026-5302 MEDIUM
Permissive Cross-domain Policy with Untrusted Domains in coolercontrold
CVSS 6.3
CVE-2026-33533 MEDIUM
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
CVSS 6.5
CVE-2026-5321 MEDIUM
vanna-ai vanna FastAPI/Flask Server cross-domain policy
CVSS 4.3
CVE-2026-34449 CRITICAL
SiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection
CVSS 9.6
CVE-2026-34237 MEDIUM
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
CVSS 6.1
CVE-2026-34227 HIGH
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface
CVSS 8.8
CVE-2026-34200 HIGH
Nhost CLI MCP Server: Missing Inbound Authentication on Explicitly Bound Network Port
CVSS 7.5
CVE-2026-0397 LOW
Information disclosure via CORS misconfiguration
CVSS 3.1
CVE-2026-33010 HIGH
mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft
CVSS 8.1
CVE-2026-33043 HIGH
AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
CVSS 8.1
CVE-2026-30924 CRITICAL
qui CORS Misconfiguration: Arbitrary Origins Trusted
CVSS 9.6
CVE-2026-32610 HIGH
Glances's Default CORS Configuration Allows Cross-Origin Credential Theft
CVSS 8.1
CVE-2026-32617 HIGH
AnythingLLM <=1.11.1 - Auth Bypass
CVSS 7.1
CVE-2026-28792 CRITICAL
TinaCMS <2.1.8 - Path Traversal
CVSS 9.6
CVE-2026-27579 HIGH
CollabPlatform - Info Disclosure
CVSS 7.4
CVE-2026-25478 HIGH
Pypi Litestar < 2.20.0 - Permissive CORS Policy
CVSS 7.4
CVE-2026-24435 MEDIUM
Shenzhen Tenda W30E V2 <16.01.0.19(5037) - XSS
CVSS 6.5
CVE-2026-1181 CRITICAL
Altium 365 - SSRF
CVSS 9.0
CVE-2026-22812 HIGH
OpenCode <1.0.216 - Command Injection
CVSS 8.8
CVE-2025-55274 LOW
HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability
CVSS 2.6
Details
Vulnerabilities 84