Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes be
Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.2
Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the
AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker
The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires
The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web manage
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint va
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware acc
Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both s
Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to pr
Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter
In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can conne
A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant
Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vu
FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API end
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6,
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit a
Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment vali
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable a
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthent
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.
A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security r
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Se
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an
Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Tool
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 thr
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege e
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via
Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin
The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,
The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu
The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly na
Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.Thi
The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due t
The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including
The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Authentication
The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ
The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and
The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started