Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-288

MITRE ↗

CWE-288

72
CRITICAL
85
HIGH
63
MEDIUM
5
LOW
249 CVEs · Page 2/5
9.8
CVE-2026-66453

Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.

9.8
CVE-2026-66465

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

9.8
CVE-2026-75627

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers

9.8
CVE-2026-74001

Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

9.8
CVE-2026-16639

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On all

9.8
CVE-2026-76943

Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to byp

9.4
CVE-2026-33950

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a

9.1
CVE-2025-68620

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two featur

9.1
CVE-2025-67039

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe

9.1
CVE-2026-8598

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not requi

9.1
CVE-2026-33843

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized

9.1
CVE-2026-58172

Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clie

9.1
CVE-2026-5268

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li

9.1
CVE-2026-75045

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download data

9.1
CVE-2026-73381

Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

8.8
CVE-2026-21411

Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass

8.8
CVE-2025-67915

Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authenticat

8.8
CVE-2025-68707

An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated ne

8.8
CVE-2026-1618

Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows

8.8
CVE-2025-67998

Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-e

8.8
CVE-2026-27390

Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add

8.8
CVE-2026-23480

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability.

8.8
CVE-2026-24359

Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentica

8.8
CVE-2026-34040

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all

8.8
CVE-2026-8697

Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service all

8.8
CVE-2026-5415

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor

8.8
CVE-2026-49062

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Ex

8.8
CVE-2026-42629

Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.

8.8
CVE-2026-22049

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnera

8.8
CVE-2026-65542

Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.

8.8
CVE-2026-50191

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account tak

8.6
CVE-2026-1603 KEV

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to

8.6
CVE-2026-68584

SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end

8.6
CVE-2026-63587

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Aut

8.4
CVE-2026-22037

The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/expr

8.2
CVE-2025-67070

A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker

8.2
CVE-2026-22731

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application

8.2
CVE-2026-22733

Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application

8.2
CVE-2026-3324

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due

8.2
CVE-2026-41059

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have

8.2
CVE-2026-40022

When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-ht

8.2
CVE-2026-42735

Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-managem

8.2
CVE-2026-50194

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati

8.1
CVE-2026-1779

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and in

8.1
CVE-2026-25471

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-gua

8.1
CVE-2026-25357

Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-member

8.1
CVE-2026-25406

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authent

8.1
CVE-2026-34581

goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token

8.1
CVE-2026-3605

An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they w

8.1
CVE-2026-44574

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applica

Frequently Asked Questions

What is CWE-288?

CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-288?

There are 249 CVE records associated with CWE-288 in our database. Of these, 72 are critical severity, 85 are high severity, and 63 are medium severity.

How can I protect against CWE-288 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.

Detect CWE-288 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.

Get Started