BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentation
Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I
Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept
The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/custome
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the fil
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated empl
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio
The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and in
Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow image-slider-slidesho
ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a
The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure D
Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulner
All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modif
The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to Insecure Direct O
A vulnerability was identified in Zhong Bang CRMEB up to 5.6.3. This affects the function detail/tidyOrder of the file /
The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is
OpenProject is an open-source, web-based project management software. Prior to 17.0.2, the drag&drop handler moving an a
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The en
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, the getSwimlane API method lacks
GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8
An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view
The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an
The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i
The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insec
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet`
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values`
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does n
Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access
LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRep
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ins
The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Inse
Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modi
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Compos
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, there is a
A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read a
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exp
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endp
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v
** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. Thi
Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through u
Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the previ
Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a cr
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started