Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-288

MITRE ↗

CWE-288

255
CRITICAL
214
HIGH
133
MEDIUM
9
LOW
651 CVEs · Page 3/14
8.1
CVE-2026-42411

Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.

8.1
CVE-2026-48970

Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.

8.1
CVE-2026-25439

Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions.

8.1
CVE-2026-56243

Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext A

8.1
CVE-2026-59545

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

8.1
CVE-2026-18577 KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu

8.1
CVE-2026-70468

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.

8.1
CVE-2026-58092

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was st

8.1
CVE-2026-82269

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middl

8.0
CVE-2026-12703

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti

7.8
CVE-2026-26117

Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized att

7.6
CVE-2026-54804

Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.

7.6
CVE-2026-66677

Subscriber Broken Authentication in Leyka <= 3.32.3 versions.

7.5
CVE-2026-22205

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows una

7.5
CVE-2026-32130

ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a Syste

7.5
CVE-2026-25002

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpres

7.5
CVE-2026-32678

Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical confi

7.5
CVE-2024-44286

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with

7.5
CVE-2026-44575

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Rou

7.5
CVE-2026-45109

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was

7.5
CVE-2026-42760

Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule

7.5
CVE-2026-40780

Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password

7.5
CVE-2026-40781

Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.

7.5
CVE-2026-42668

Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.

7.5
CVE-2020-37255

WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attack

7.5
CVE-2026-56029

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

7.5
CVE-2026-57697

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profil

7.5
CVE-2026-72691

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at

7.5
CVE-2026-32481

Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.

7.4
CVE-2026-12579

AS228T with Authentication Bypass Vulnerability

7.4
CVE-2026-18556 KEV

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.

7.3
CVE-2026-27707

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and

7.3
CVE-2026-8321

A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the f

7.3
CVE-2026-24206

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes

7.3
CVE-2026-42745

Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-o

7.3
CVE-2026-78259

Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

7.2
CVE-2026-22572

An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3,

7.1
CVE-2026-42749

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types

7.1
CVE-2026-42654

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows

7.1
CVE-2026-39450

Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.

7.1
CVE-2026-40785

Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.

7.1
CVE-2026-73396

Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.

7.1
CVE-2026-24185

NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while

6.8
CVE-2026-2745

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 1

6.8
CVE-2026-36175

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and

6.8
CVE-2026-36028

A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass

6.8
CVE-2026-18636

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr

6.7
CVE-2026-22341

Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authenticatio

6.5
CVE-2026-0948

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Pri

6.5
CVE-2020-37156

BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard wi

Frequently Asked Questions

What is CWE-288?

CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-288?

There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.

How can I protect against CWE-288 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.

Detect CWE-288 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.

Get Started