The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through Us
A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlle
Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller ag
e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the applicati
Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout
The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i
EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:
Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil
Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil
Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass sam
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can e
Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut
Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a
Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that
Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <=
OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint a
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce
Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permis
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing t
Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.
LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic sea
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the
Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly
n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior
Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js use
SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation at
Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any
TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints t
Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D
Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{i
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tr
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industr
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa
Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure D
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started