Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-639

MITRE ↗

CWE-639

174
CRITICAL
645
HIGH
1,343
MEDIUM
96
LOW
2,420 CVEs · Page 15/49
5.4
CVE-2026-13549

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function d

5.4
CVE-2026-14614

A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP)

5.4
CVE-2026-55478

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether th

5.4
CVE-2026-12393

The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requ

5.4
CVE-2026-63745

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof compos

5.4
CVE-2026-44585

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the

5.4
CVE-2026-14184

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of

5.4
CVE-2026-61064

Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Install / Upgrade Issues). Supp

5.4
CVE-2026-65463

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

5.4
CVE-2026-65696

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip

5.4
CVE-2026-48052

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i

5.4
CVE-2026-14224

The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data

5.4
CVE-2026-14310

The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread

5.4
CVE-2026-12697

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us

5.4
CVE-2026-8155

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints

5.4
CVE-2026-16574

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that

5.4
CVE-2026-15238

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer reco

5.4
CVE-2026-19579

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request

5.4
CVE-2026-68076

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'

5.4
CVE-2026-58435

Gitea LFS Deploy-Key Privilege Escalation

5.4
CVE-2026-73039

streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated

5.4
CVE-2026-19966

A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown pro

5.4
CVE-2026-45120

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status c

5.4
CVE-2026-59992

Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azu

5.4
CVE-2026-76263

In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles coul

5.4
CVE-2026-54553

Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applica

5.4
CVE-2026-54256

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

5.4
CVE-2026-81668

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the paren

5.3
CVE-2026-24599

Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-li

5.3
CVE-2026-24634

Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Ex

5.3
CVE-2026-0909

The WP ULike plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including

5.3
CVE-2026-24991

Authorization Bypass Through User-Controlled Key vulnerability in HT Plugins Extensions For CF7 extensions-for-cf7 allow

5.3
CVE-2026-1271

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref

5.3
CVE-2026-25757

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2,

5.3
CVE-2025-13842

The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions

5.3
CVE-2026-25005

Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploade

5.3
CVE-2026-25324

Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master

5.3
CVE-2026-1219

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Dir

5.3
CVE-2026-3185

A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /

5.3
CVE-2026-28225

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on

5.3
CVE-2026-1558

The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to,

5.3
CVE-2026-29069

Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() end

5.3
CVE-2026-30231

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.

5.3
CVE-2026-30857

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.

5.3
CVE-2026-30885

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al

5.3
CVE-2026-2888

The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all ve

5.3
CVE-2025-69727

An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (

5.3
CVE-2026-33425

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenti

5.3
CVE-2026-23488

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an una

5.3
CVE-2026-33160

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R

Frequently Asked Questions

What is CWE-639?

CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-639?

There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.

How can I protect against CWE-639 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.

Detect CWE-639 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.

Get Started