Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object
Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download
Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont
diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders,
TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,
The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and d
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team
Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload
Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying th
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipu
Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied inpu
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ins
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation f
Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versi
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in ser
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being
Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in model
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows a
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(repo
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned get
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account w
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerab
Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Fu
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authen
The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up
The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including
A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel o
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other org
A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissio
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started