CWE-472— External Control of Assumed-Immutable Web Parameter
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.— MITRE CWE catalog
160 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-472page 3 of 4
- CVE-2026-11044MEDIUMCVSS 6.5EG 6.52026-06-04
Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-10018MEDIUMCVSS 6.5EG 6.52026-05-28
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-9882MEDIUMCVSS 6.5EG 6.52026-05-28
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2025-30152MEDIUMCVSS 6.5EG 6.52025-03-19
The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows users to modify their shopping cart after completing the PayPal Checkout proc…
- CVE-2025-29788MEDIUMCVSS 6.5EG 6.52025-03-17
The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 allows users to manipulate the final payment amount processed by PayPal. If a user m…
- CVE-2023-38520MEDIUMCVSS 6.5EG 6.52024-06-04
External Control of Assumed-Immutable Web Parameter vulnerability in PINPOINT.WORLD Pinpoint Booking System allows Functionality Misuse.This issue affects Pinpoint Booking System: from n/a through 2.9.9.3.4.
- CVE-2026-56877MEDIUMCVSS 6.3EG 6.32026-07-13
The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against the authenticated SCORM session token. An authenticated user can substitute arbitrary userId…
- CVE-2026-107363MEDIUMCVSS 6.1EG 6.12026-10-07
In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may substitu…
- CVE-2026-16089MEDIUMCVSS 5.9EG 5.92026-07-17
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an …
- CVE-2023-28512MEDIUMCVSS 5.9EG 5.92024-03-03
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improper input validation. IBM X-Force ID: 250396.
- CVE-2026-84654MEDIUMCVSS 5.4EG 5.42026-09-02
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing …
- CVE-2024-50703MEDIUMCVSS 5.4EG 5.42024-12-30
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
- CVE-2026-105322MEDIUMCVSS 5.3EG 5.32026-10-07
The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay).
- CVE-2026-91020MEDIUMCVSS 5.3EG 5.32026-10-02
The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item price and store-credit coupon value, allowing unauthenticated users to s…
- CVE-2026-90987MEDIUMCVSS 5.3EG 5.32026-10-02
The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase.
- CVE-2026-86838MEDIUMCVSS 5.3EG 5.32026-09-28
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for f…
- CVE-2026-85010MEDIUMCVSS 5.3EG 5.32026-09-21
The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place order…
- CVE-2026-84762MEDIUMCVSS 5.3EG 5.32026-09-03
Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
- CVE-2026-77794MEDIUMCVSS 5.3EG 5.32026-09-02
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an …
- CVE-2026-16067MEDIUMCVSS 5.3EG 5.32026-08-06
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re…
- CVE-2026-15149MEDIUMCVSS 5.3EG 5.32026-08-06
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to cre…
- CVE-2026-1982MEDIUMCVSS 5.3EG 5.32026-07-30
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side v…
- CVE-2026-7484MEDIUMCVSS 5.3EG 5.32026-07-24
External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: before 202606251646.
- CVE-2026-59817MEDIUMCVSS 5.3EG 5.32026-07-09
Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal pa…
- CVE-2026-14391MEDIUMCVSS 5.3EG 5.32026-07-02
Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chrom…
- CVE-2026-11678MEDIUMCVSS 5.3EG 5.32026-06-08
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secur…
- CVE-2026-11669MEDIUMCVSS 5.3EG 5.32026-06-08
Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (C…
- CVE-2026-32699MEDIUMCVSS 5.3EG 5.32026-05-05
FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevent…
- CVE-2026-4911MEDIUMCVSS 5.3EG 5.32026-04-28
The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentInte…
- CVE-2026-2519MEDIUMCVSS 5.3EG 5.32026-04-09
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplie…
- CVE-2025-3743MEDIUMCVSS 5.3EG 5.32025-04-25
The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulat…
- CVE-2025-26312MEDIUMCVSS 5.3EG 5.32025-03-14
SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.
- CVE-2024-12123MEDIUMCVSS 5.3EG 5.32024-12-04
A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. When an authenticated user submits a ticket, the request can be intercepted and subsequently modified b…
- CVE-2024-6010MEDIUMCVSS 5.3EG 5.32024-09-07
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to the plugin allowing the price field to be manipulated prior to processing via the 'create_…
- CVE-2024-3649MEDIUMCVSS 5.3EG 5.32024-05-02
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. Thi…
- CVE-2024-22049MEDIUMCVSS 5.3EG 5.32024-01-04
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker cont…
- CVE-2022-30597MEDIUMCVSS 5.3EG 5.32022-05-18
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
- CVE-2021-27769MEDIUMCVSS 5.3EG 5.32022-05-12
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to occur. Overall, any …
- CVE-2019-13927MEDIUMCVSS 5.3EG 5.32019-12-12
A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controll…
- CVE-2020-1765MEDIUMCVSS 3.5EG 5.32020-01-10
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Community Edition 5.0.x…
- CVE-2026-11290MEDIUMCVSS 5.0EG 5.02026-06-04
Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)
- CVE-2026-11281MEDIUMCVSS 5.0EG 5.02026-06-04
Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)
- CVE-2025-67846MEDIUMCVSS 4.9EG 4.92025-12-19
The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can iden…
- CVE-2026-9911MEDIUMCVSS 4.3EG 4.32026-05-28
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-8567MEDIUMCVSS 4.3EG 4.32026-05-14
Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-8559MEDIUMCVSS 4.3EG 4.32026-05-14
Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-7969MEDIUMCVSS 4.3EG 4.32026-05-06
Integer overflow in Network in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-7942MEDIUMCVSS 4.3EG 4.32026-05-06
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-7340MEDIUMCVSS 4.3EG 4.32026-04-28
Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-4453MEDIUMCVSS 4.3EG 4.32026-03-20
Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Map vulnerabilities like CWE-472 to your infrastructure
EchelonGraph correlates every CVE — across CWE-472 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →