stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quara
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirecto
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_i
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authent
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. W
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. Whe
ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functiona
ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authent
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 thro
Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An
Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauth
Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 all
Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of
The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user
The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to se
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target
The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in
The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for c
The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modi
The permission check for the frontend management update flow verified a different event than the one the request went on
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML
TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another work
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticate
KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Eve
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.
Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue acr
Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-conf
Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection.
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an
The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and
The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all
An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. Th
The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0.
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi
The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin
Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore all
The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin user
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started