Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Ma
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance f
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphin
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers wi
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardc
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to
There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commo
Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does n
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal as
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive con
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in ad
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Pa
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain
svelte performance oriented web framework. Prior to 5.51.5, in server-side rendering, attribute spreading on elements (e
Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows f
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache A
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulne
K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by inc
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user
FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticat
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id,
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the P
rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitr
Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipula
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulne
Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnera
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an improper author
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATC
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versi
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management function
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP
Frequently Asked Questions
What is CWE-915?
CWE-915 (CWE-915) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-915?
There are 121 CVE records associated with CWE-915 in our database. Of these, 18 are critical severity, 50 are high severity, and 33 are medium severity.
How can I protect against CWE-915 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-915 using AI-powered security agents.
Detect CWE-915 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-915 vulnerabilities across your infrastructure.
Get Started