SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queri
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the
ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family re
FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2
Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they w
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mas
Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote att
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows
HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cr
Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only acc
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multi
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vu
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-ma
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authen
OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion en
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credent
MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/tradin
Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure
An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attac
An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and rep
A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to exec
Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-d
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an
SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticat
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/fil
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authe
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint t
Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Ag
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete op
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started