Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Ob
The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin
A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information d
PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL wo
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in ver
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1
A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/con
A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function getAuthorizedSpaces of t
The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Obje
The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in al
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference
The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared
Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration change
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin
The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment
A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han
A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplie
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg
The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure
A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to
The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboa
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored cust
The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing
The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i
The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify produc
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync
When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10
The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co
A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe
A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the calle
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started