Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.
Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext A
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.
In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was st
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middl
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti
Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized att
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows una
ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a Syste
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpres
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical confi
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Rou
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was
Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule
Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attack
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profil
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
AS228T with Authentication Bypass Vulnerability
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the f
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-o
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3,
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows
Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.
Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 1
An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and
A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr
Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authenticatio
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Pri
BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard wi
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started