Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.
An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are
An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authentica
Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).
The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check author
The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher
The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spo
The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a websit
Online Birth Certificate Management System version 1.0 suffers from an Insecure Direct Object Reference (IDOR) vulnerabi
The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.5 does not properly check for the upload size limit
Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 thro
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPr
The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including,
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Br
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuth
Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPres
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the
An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions startin
An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6
Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthentica
A vulnerability has been identified in Industrial Edge Management (All versions < V1.3). An unauthenticated attacker cou
ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC i
An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privil
The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authen
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13
ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct a
An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remot
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an imprope
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, compani
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.
The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arb
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexCon
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Uplo
Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visib
sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Obj
In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Ref
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of p
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started