CWE-348— Use of Less Trusted Source
The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.— MITRE CWE catalog
87 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-348page 2 of 2
- CVE-2026-87070MEDIUMCVSS 5.3EG 5.32026-09-23
The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its per…
- CVE-2026-59897MEDIUMCVSS 5.3EG 5.32026-07-08
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a subst…
- CVE-2026-57942MEDIUMCVSS 5.3EG 5.32026-06-29
LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses by injecting arbitrary values into the X-F…
- CVE-2026-33690MEDIUMCVSS 5.3EG 5.32026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client's IP address. An attacker can spoof t…
- CVE-2026-22201MEDIUMCVSS 5.3EG 5.32026-03-13
wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_…
- CVE-2025-13694MEDIUMCVSS 5.3EG 5.32026-01-07
The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This is due to the plugin trusting user-supplied headers such as HTTP_X_FORWARDED_FOR to determine the client's IP addr…
- CVE-2025-15154MEDIUMCVSS 5.3EG 5.32025-12-28
A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For le…
- CVE-2025-53522MEDIUMCVSS 5.3EG 5.32025-08-20
Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unauthenticated attacker.
- CVE-2025-47149MEDIUMCVSS 5.3EG 5.32025-05-23
The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If exploited, the product may treat an unauthorized pattern file as an authorized. If the product uses a specially crafted pat…
- CVE-2022-4534MEDIUMCVSS 5.3EG 5.32024-10-08
The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for…
- CVE-2022-4533MEDIUMCVSS 5.3EG 5.32024-09-19
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request lo…
- CVE-2022-4529MEDIUMCVSS 5.3EG 5.32024-09-05
The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due to insufficient restrictions on where the IP Address information is being retrieved …
- CVE-2022-4539MEDIUMCVSS 5.3EG 5.32024-08-31
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request log…
- CVE-2022-4536MEDIUMCVSS 5.3EG 5.32024-08-31
The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request loggi…
- CVE-2024-6171MEDIUMCVSS 5.3EG 5.32024-07-09
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-sup…
- CVE-2024-0789MEDIUMCVSS 5.3EG 5.32024-06-19
The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval…
- CVE-2023-35906MEDIUMCVSS 5.3EG 5.32023-09-05
IBM Aspera Faspex 5.0.5 could allow a remote attacked to bypass IP restrictions due to improper access controls. IBM X-Force ID: 259649.
- CVE-2026-26927MEDIUMCVSS 5.1EG 5.12026-04-02
Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched. In Szafir SDK Web it is possible to change the URL (HTTP Origin) of the application call location. An unauthenticated…
- CVE-2026-63220MEDIUMCVSS 4.8EG 4.82026-07-31
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and …
- CVE-2026-54289MEDIUMCVSS 4.8EG 4.82026-06-16
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes ea…
- CVE-2026-102630MEDIUMCVSS 4.7EG 4.72026-09-29
UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can …
- CVE-2026-92530MEDIUMCVSS 4.3EG 4.32026-09-23
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request authors…
- CVE-2026-84718MEDIUMCVSS 4.3EG 4.32026-09-23
A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it origi…
- CVE-2026-90679MEDIUMCVSS 4.3EG 4.32026-09-13
Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an in…
- CVE-2025-32900MEDIUMCVSS 4.3EG 4.32025-12-05
In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, K…
- CVE-2025-24856MEDIUMCVSS 4.2EG 4.22025-03-16
An issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows a pre-hijacking attack, leading to Account Takeover. The attack can only be exploited if the followi…
- CVE-2024-54840MEDIUMCVSS 4.2EG 4.22025-02-03
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
- CVE-2026-78015LOWCVSS 3.7EG 3.72026-10-09
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Less Trusted Source vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to I…
- CVE-2026-25552LOWCVSS 3.7EG 3.72026-07-31
Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers c…
- CVE-2026-50243LOWCVSS 3.7EG 3.72026-07-22
In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler …
- CVE-2022-44593LOWCVSS 3.7EG 3.72024-06-21
Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.
- CVE-2023-2897LOWCVSS 3.7EG 3.72023-06-09
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP header for the purpose o…
- CVE-2025-58422LOWCVSS 3.1EG 3.12025-09-08
RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If an attacker can perform a man-in-the-middle attack, they may alter the values of HTTP requests, which could result in tampering with the oper…
- CVE-2024-10977LOWCVSS 3.1EG 3.12024-11-14
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error …
- CVE-2026-46466LOWCVSS 2.7EG 2.72026-07-03
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less tru…
- CVE-2025-48825LOWCVSS 2.5EG 2.52025-06-13
RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL wi…
- CVE-2026-105051LOWCVSS 1.9EG 1.92026-10-02
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
Map vulnerabilities like CWE-348 to your infrastructure
EchelonGraph correlates every CVE — across CWE-348 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →