A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor
The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticate
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur
The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen
The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va
The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that retu
vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_functi
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Uni
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership che
Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessi
Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its mult
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (rel
The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc
The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token
Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attac
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /as
OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a
A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/mai
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to f
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authoriz
A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:pr
A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming w
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started