Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-639

MITRE ↗

CWE-639

174
CRITICAL
645
HIGH
1,343
MEDIUM
96
LOW
2,420 CVEs · Page 21/49
4.3
CVE-2026-13177

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user

4.3
CVE-2026-13612

The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al

4.3
CVE-2026-14857

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his

4.3
CVE-2026-14858

The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi

4.3
CVE-2026-18962

The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int

4.3
CVE-2026-72650

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Fu

4.3
CVE-2026-19784

A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Disciplin

4.3
CVE-2026-19836

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality

4.3
CVE-2026-19838

A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the

4.3
CVE-2025-10005

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure

4.3
CVE-2026-12905

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7

4.3
CVE-2026-66634

Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

4.3
CVE-2026-14196

The WCFM Marketplace WordPress plugin before 3.8.1 does not verify that a marketplace vendor owns a review before allow

4.3
CVE-2026-16979

The SmartCrawl SEO checker, analyzer & optimizer WordPress plugin before 3.16.3 does not perform capability checks on tw

4.3
CVE-2026-19416

The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified

4.3
CVE-2026-61663

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

4.3
CVE-2026-62945

TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-contr

4.3
CVE-2026-77116

Brave Popup Builder (slug: brave-popup-builder) has a broken access control issue in versions through 0.8.5. Any logged-

4.3
CVE-2026-10630

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress

4.3
CVE-2026-78466

The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and

4.3
CVE-2026-80197

Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints

4.3
CVE-2026-74930

The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the

4.3
CVE-2026-77789

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to th

4.3
CVE-2026-79654

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a

4.3
CVE-2026-16568

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe

4.3
CVE-2026-78139

The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one

4.3
CVE-2026-79995

The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email c

4.3
CVE-2026-81299

Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.

4.3
CVE-2026-80311

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to th

4.2
CVE-2025-68492

Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln

4.2
CVE-2026-2010

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function P

4.2
CVE-2026-43883

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.jso

4.2
CVE-2026-65699

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica

4.2
CVE-2026-73657

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4,

4.2
CVE-2026-78581

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Acce

3.8
CVE-2025-47555

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly

3.8
CVE-2026-22404

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorr

3.8
CVE-2026-22406

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorr

3.8
CVE-2026-22407

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly

3.8
CVE-2026-22409

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Inco

3.8
CVE-2026-22411

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorr

3.8
CVE-2026-14197

The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket

3.8
CVE-2026-14211

The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl

3.7
CVE-2026-23522

LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKno

3.7
CVE-2026-8196

A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/je

3.7
CVE-2026-9306

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourne

3.7
CVE-2026-24761

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil

3.7
CVE-2026-6976

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an

3.7
CVE-2026-13490

A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document

3.7
CVE-2026-14927

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che

Frequently Asked Questions

What is CWE-639?

CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-639?

There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.

How can I protect against CWE-639 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.

Detect CWE-639 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.

Get Started