The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server pas
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server com
Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard
Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Norm
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account t
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including,
An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to
An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Se
Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authenticati
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo
Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU India PayU India payu-india allows Authen
CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authen
An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an at
The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due t
The AXIS Camera Station Server had a flaw that allowed to bypass authentication that is normally required.
The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0
The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization wi
The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and
Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of th
In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through fo
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati
Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCom
An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110.
There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can
The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due
The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.
An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gai
Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.Th
Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Auth
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to ins
The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. Thi
The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1
The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeo
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl
The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve
Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-l
The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Elated-Themes Search & Go search-and-go allows
An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel
An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to
The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across dev
The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,
Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder a
Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects AB
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes defa
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started