Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/
Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5.
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I
The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all v
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth
Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7.
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h`
When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause
Frequently Asked Questions
What is CWE-289?
CWE-289 (CWE-289) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-289?
There are 19 CVE records associated with CWE-289 in our database. Of these, 8 are critical severity, 4 are high severity, and 5 are medium severity.
How can I protect against CWE-289 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-289 using AI-powered security agents.
Detect CWE-289 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-289 vulnerabilities across your infrastructure.
Get Started