Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-639

MITRE ↗

CWE-639

174
CRITICAL
645
HIGH
1,343
MEDIUM
96
LOW
2,420 CVEs · Page 17/49
5.3
CVE-2026-15622

A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor

5.3
CVE-2026-11966

The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticate

5.3
CVE-2026-3482

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.

5.3
CVE-2026-65501

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

5.3
CVE-2026-13464

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob

5.3
CVE-2026-13345

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility

5.3
CVE-2026-15255

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in

5.3
CVE-2026-15257

The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr

5.3
CVE-2026-14843

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target

5.3
CVE-2026-17567

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne

5.3
CVE-2025-14073

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur

5.3
CVE-2026-16981

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa

5.3
CVE-2026-14313

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-

5.3
CVE-2026-28180

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

5.3
CVE-2026-14842

The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b

5.3
CVE-2026-15147

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen

5.3
CVE-2026-68870

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va

5.3
CVE-2026-16737

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca

5.3
CVE-2026-72802

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that retu

5.3
CVE-2026-18750

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_functi

5.3
CVE-2026-74242

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Uni

5.3
CVE-2026-12998

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D

5.3
CVE-2026-14832

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership che

5.3
CVE-2026-16309

Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessi

5.3
CVE-2026-74009

Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.

5.3
CVE-2026-16058

The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its mult

5.3
CVE-2026-78278

Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.

5.3
CVE-2026-13404

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (rel

5.3
CVE-2026-3235

The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc

5.3
CVE-2026-16567

The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token

5.3
CVE-2026-82290

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attac

5.3
CVE-2026-82602

A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /as

5.0
CVE-2026-30959

OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au

5.0
CVE-2026-7573

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a

5.0
CVE-2026-11500

A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f

5.0
CVE-2026-42862

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass

5.0
CVE-2026-13534

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/mai

5.0
CVE-2026-27881

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.

5.0
CVE-2026-27883

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.

5.0
CVE-2026-59100

LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to

5.0
CVE-2026-34167

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.

5.0
CVE-2026-59253

n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to f

5.0
CVE-2026-55515

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authoriz

5.0
CVE-2026-17531

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality

5.0
CVE-2026-55067

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v

4.9
CVE-2026-33700

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:pr

4.9
CVE-2026-37978

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th

4.9
CVE-2026-9708

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming w

4.9
CVE-2026-45330

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3

4.9
CVE-2026-17018

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric

Frequently Asked Questions

What is CWE-639?

CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-639?

There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.

How can I protect against CWE-639 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.

Detect CWE-639 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.

Get Started