The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects
The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.1
The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all ve
The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versi
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricte
The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2
A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course ba
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information E
The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere El
The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in
The If-So Dynamic Content Personalization plugin for WordPress is vulnerable to Information Exposure in all versions up
The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all ve
The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in
The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t
The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in
The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in a
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to
The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,
The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure in
The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Informatio
An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows una
Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthori
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all ver
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable
The Get Post Content Shortcode plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up
The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu
The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc
An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unau
An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to
The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi
Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR
OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the Op
iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in t
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information
A vulnerability classified as problematic was found in Sovell Smart Canteen System up to 3.0.7303.30513. Affected by thi
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of t
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is s
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5,
Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through
Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where
Organization admins can delete pending invites created in an organization they are not part of.
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure
Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft
Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authenticati
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started