Dell Mobility - E-Lab Navigator, version(s) 3.1.9, 3.2.0, contain(s) an Authorization Bypass Through User-Controlled Key
An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 b
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in al
The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi
The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refere
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Insecure
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_
The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid :
Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects Boo
The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability
Authorization Bypass Through User-Controlled Key vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall:
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid :
Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider.This issue affects Crelly
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missi
A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affe
ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow
The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation
The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in t
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere
The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl
The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a
The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc
The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an
An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.
zot is an OCI image registry. Prior to 2.1.0, the cache driver `GetBlob()` allows read access to any blob without access
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a t
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability
Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to
The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio
Authorization Bypass Through User-Controlled Key vulnerability in masteriyo Masteriyo - LMS learning-management-system.T
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo F
The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Refe
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects
An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulner
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Aff
Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-syst
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp
An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the pa
The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu
The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including
The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Informatio
The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 vi
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started