CWE-472— External Control of Assumed-Immutable Web Parameter
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.— MITRE CWE catalog
160 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-472page 4 of 4
- CVE-2025-54551MEDIUMCVSS 4.3EG 4.32025-08-20
Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control of Web parameter. If exploited, a user of the product may escalate the privilege and access data that the user do not …
- CVE-2025-54832MEDIUMCVSS 4.3EG 4.32025-07-31
OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.
- CVE-2025-43002MEDIUMCVSS 4.3EG 4.32025-05-13
SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application ar…
- CVE-2025-31327MEDIUMCVSS 4.3EG 4.32025-04-22
SAP Field Logistics Manage Logistics application OData meta-data property is vulnerable to data tampering, due to which certain fields could be externally modified by an attacker causing low impact on integrity of the application. Confiden…
- CVE-2025-31333MEDIUMCVSS 4.3EG 4.32025-04-08
SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.
- CVE-2026-7912MEDIUMCVSS 4.2EG 4.22026-05-06
Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-24373LOWCVSS 3.7EG 3.72024-06-03
External Control of Assumed-Immutable Web Parameter vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Manipulating Hidden Fields.This issue affects Booking calendar, Appointment Booking System: from n/a through …
- CVE-2025-32816LOWCVSS 3.1EG 3.12025-04-11
CodeLit CourseLit before 0.57.5 allows Parameter Tampering via a payment plan associated with the wrong entity.
- CVE-2025-27893LOWCVSS 1.8EG 1.82025-03-11
In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?…
- CVE-2025-59382LOWCVSS 1.2EG 1.22026-06-10
QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
Map vulnerabilities like CWE-472 to your infrastructure
EchelonGraph correlates every CVE — across CWE-472 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →