A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function d
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP)
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether th
The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requ
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the
The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supp
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip
Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data
The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'
Gitea LFS Deploy-Key Privilege Escalation
streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated
A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown pro
MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status c
Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azu
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles coul
Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applica
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the paren
Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-li
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Ex
The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including
Authorization Bypass Through User-Controlled Key vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allow
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2,
The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions
Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploade
Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Dir
A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on
The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to,
Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() end
Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al
The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all ve
An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenti
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an una
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started