Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-639

MITRE ↗

CWE-639

174
CRITICAL
645
HIGH
1,343
MEDIUM
96
LOW
2,420 CVEs · Page 20/49
4.3
CVE-2026-27956

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.

4.3
CVE-2026-12904

The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Ob

4.3
CVE-2026-10096

The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin

4.3
CVE-2026-5138

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information d

4.3
CVE-2026-58653

PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL wo

4.3
CVE-2026-11900

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in ver

4.3
CVE-2026-14608

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1

4.3
CVE-2026-14793

A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/con

4.3
CVE-2026-15036

A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function getAuthorizedSpaces of t

4.3
CVE-2026-12433

The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Obje

4.3
CVE-2026-12400

The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in al

4.3
CVE-2026-13116

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference

4.3
CVE-2026-10041

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al

4.3
CVE-2026-10103

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared

4.3
CVE-2026-6541

Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration change

4.3
CVE-2026-9341

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di

4.3
CVE-2026-54568

Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c

4.3
CVE-2026-57205

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions

4.3
CVE-2026-15945

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin

4.3
CVE-2026-15159

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up

4.3
CVE-2026-48016

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment

4.3
CVE-2026-16075

A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat

4.3
CVE-2026-14183

The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han

4.3
CVE-2026-16450

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the

4.3
CVE-2026-63259

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplie

4.3
CVE-2026-65456

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

4.3
CVE-2026-17570

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg

4.3
CVE-2026-16797

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure

4.3
CVE-2026-63242

A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to

4.3
CVE-2026-13145

The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboa

4.3
CVE-2026-14223

The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored cust

4.3
CVE-2026-12376

The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing

4.3
CVE-2026-14847

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i

4.3
CVE-2026-14938

The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be

4.3
CVE-2026-16291

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo

4.3
CVE-2026-15260

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in

4.3
CVE-2026-16564

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order

4.3
CVE-2026-16565

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify produc

4.3
CVE-2026-69094

Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu

4.3
CVE-2026-70488

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync

4.3
CVE-2025-11850

When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us

4.3
CVE-2026-66692

Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10

4.3
CVE-2026-14306

The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co

4.3
CVE-2026-19064

A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe

4.3
CVE-2026-19066

A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk

4.3
CVE-2026-15214

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription

4.3
CVE-2026-17020

The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the calle

4.3
CVE-2026-18200

The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user

4.3
CVE-2026-72724

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c

4.3
CVE-2026-66764

Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user

Frequently Asked Questions

What is CWE-639?

CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-639?

There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.

How can I protect against CWE-639 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.

Detect CWE-639 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.

Get Started