The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for Wor
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec
Umbraco is a free and open source .NET content management system. An improper API access control issue has been identifi
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is
A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of
A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown
A vulnerability was found in FoxCMS 1.25 and classified as problematic. Affected by this issue is some unknown functiona
A vulnerability has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0 and classified as problem
A vulnerability classified as problematic has been found in huanfenz/code-projects StudentManager up to 1.0. This affect
A vulnerability, which was classified as problematic, was found in veal98 小牛肉 Echo 开源社区系统 4.2. Affected is the function
A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vu
A vulnerability classified as problematic was found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System 1.0. Thi
A vulnerability, which was classified as problematic, has been found in wowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstatio
A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f16
A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as c
A vulnerability classified as problematic was found in 70mai 1S up to 20250611. This vulnerability affects unknown code
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown fun
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all
A vulnerability was found in Portabilis i-Educar up to 2.9.0. It has been classified as problematic. This affects an unk
A vulnerability was found in Portabilis i-Educar up to 2.9.0. It has been declared as critical. This vulnerability affec
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of
The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on th
A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/
A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file
A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the f
A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Ap
A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /a
A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of th
A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the fun
A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController o
A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of t
A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /b
A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponC
A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /top
A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of
A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogControlle
A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /s
A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/ro
A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/p
A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXl
A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4. This vulnerability affects
A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected element is an unknown functi
An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 t
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modific
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an act
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of othe
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a
Frequently Asked Questions
What is CWE-285?
CWE-285 (CWE-285) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-285?
There are 1,548 CVE records associated with CWE-285 in our database. Of these, 120 are critical severity, 432 are high severity, and 860 are medium severity.
How can I protect against CWE-285 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-285 using AI-powered security agents.
Detect CWE-285 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-285 vulnerabilities across your infrastructure.
Get Started