Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-288

MITRE ↗

CWE-288

255
CRITICAL
214
HIGH
133
MEDIUM
9
LOW
651 CVEs · Page 5/14
4.2
CVE-2025-13986

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality

3.5
CVE-2025-13475

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes be

2.7
CVE-2026-34372

Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.2

2.4
CVE-2025-68710

Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with

2.4
CVE-2025-68708

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the

2.4
CVE-2025-68711

AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker

CVE-2026-2540

The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires

CVE-2026-1241

The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage

CVE-2026-40582

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint va

CVE-2026-42300

DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware acc

CVE-2026-42303

Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s

CVE-2026-4320

Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to pr

CVE-2026-35087

Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter

CVE-2026-35090

In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can conne

CVE-2026-8990

A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant

CVE-2026-45577

Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public

CVE-2026-12225

syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vu

CVE-2026-33543

FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API end

CVE-2026-55666

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6,

CVE-2026-57867

MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit a

CVE-2026-39385

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment vali

CVE-2026-61425

Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable a

CVE-2026-43945

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthent

CVE-2026-8338

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.

CVE-2026-33591

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security r

CVE-2026-18574

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Se

CVE-2026-58073

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an

CVE-2026-71879

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Tool

CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr

CVE-2026-65641

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

9.8
CVE-2024-12402

The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege e

9.8
CVE-2024-55591 KEV

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro

9.8
CVE-2024-12857

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi

9.8
CVE-2025-0364

BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via

9.8
CVE-2025-0674

Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the

9.8
CVE-2025-1061

The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin

9.8
CVE-2025-0316

The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including

9.8
CVE-2025-0181

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,

9.8
CVE-2024-13182

The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu

9.8
CVE-2025-1283

The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly na

9.8
CVE-2025-26966

Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.Thi

9.8
CVE-2025-1564

The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due t

9.8
CVE-2025-1638

The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including

9.8
CVE-2025-1671

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including

9.8
CVE-2025-27658

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Authentication

9.8
CVE-2025-1515

The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ

9.8
CVE-2025-1315

The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and

9.8
CVE-2024-13446

The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and

9.8
CVE-2024-11286

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th

9.8
CVE-2024-13771

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass

Frequently Asked Questions

What is CWE-288?

CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-288?

There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.

How can I protect against CWE-288 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.

Detect CWE-288 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.

Get Started