Authentication Bypass Using an Alternate Path or Channel vulnerability in ahachat AhaChat Messenger Marketing ahachat-me
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when
EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who
OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classifica
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.Thi
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal OpenID Connect / OAuth client allows Au
Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a sec
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, a
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommer
Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.
Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.
Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover
Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooComm
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass t
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching fo
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Cust
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file pa
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web
GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileg
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attac
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Func
Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navig
OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks an
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback invokes that allows
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query handling that allows
OpenClaw before 2026.3.25 contains an authentication bypass vulnerability in raw card send surface that allows unpaired
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote informa
An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malici
OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasReq
OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authenticati
A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a
GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 1
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, the Caldav endpoint allows login
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypa
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireM
Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started