Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref
Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulner
Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up
Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.deta
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R
solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organiza
Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorr
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiti
n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated use
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of ot
OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected s
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated au
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /t
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoo
Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project mem
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerabili
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerabili
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can en
Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains
OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas`
A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/
BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows vie
A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across differen
IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build
A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an
During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to p
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use
The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the fu
Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint all
ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any a
ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever th
ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object —
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started