CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,992 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 18 of 60
- CVE-2025-53208HIGHCVSS 7.5EG 7.52025-08-20
Authorization Bypass Through User-Controlled Key vulnerability in paymayapg Maya Business paymaya-checkout-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Maya Business: from n/a through <…
- CVE-2025-51628HIGHCVSS 7.5EG 7.52025-08-05
Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and below allows unauthenticated attackers to read confidential documents via the DocumentoId parameter.
- CVE-2025-51869HIGHCVSS 7.5EG 7.52025-07-21
Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, thread_id, and message_id parameters to the v1/space/{space_id}/thread/{thread_id}/message/…
- CVE-2025-51868HIGHCVSS 7.5EG 7.52025-07-21
Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.
- CVE-2025-4129HIGHCVSS 7.5EG 7.52025-07-21
Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers. This issue affects PAVO Pay: before 13.05.2025.
- CVE-2025-1469HIGHCVSS 7.5EG 7.52025-07-21
Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers. This issue affects Eyotek: before 11.03.2025.
- CVE-2025-3091HIGHCVSS 7.5EG 7.52025-06-24
An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.
- CVE-2025-40661HIGHCVSS 7.5EG 7.52025-06-10
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/s…
- CVE-2025-40660HIGHCVSS 7.5EG 7.52025-06-10
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/select node/dat…
- CVE-2025-40659HIGHCVSS 7.5EG 7.52025-06-10
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/f…
- CVE-2025-40658HIGHCVSS 7.5EG 7.52025-06-10
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/f…
- CVE-2025-5182HIGHCVSS 7.5EG 7.52025-05-26
A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability affects unknown code of the component Listing Handler. The manipulation leads to authorizat…
- CVE-2025-27939HIGHCVSS 7.5EG 7.52025-04-15
An attacker can change registered email addresses of other users and take over arbitrary accounts.
- CVE-2025-22931HIGHCVSS 7.5EG 7.52025-04-03
An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members.
- CVE-2024-13558HIGHCVSS 7.5EG 7.52025-03-20
The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauth…
- CVE-2024-11137HIGHCVSS 7.5EG 7.52025-03-20
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the score data of any run by manipulating the id …
- CVE-2025-0352HIGHCVSS 7.5EG 7.52025-02-20
Rapid Response Monitoring My Security Account App utilizes an API that could be exploited by an attacker to modify request data, potentially causing the API to return information about other users.
- CVE-2024-39033HIGHCVSS 7.5EG 7.52025-02-06
In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.
- CVE-2024-13694HIGHCVSS 7.5EG 7.52025-01-30
The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file()…
- CVE-2024-4464HIGHCVSS 7.5EG 7.52024-12-18
Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.
- CVE-2024-11318HIGHCVSS 7.5EG 7.52024-11-18
An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the session of an unauthenticated user by brute-force attacking t…
- CVE-2024-43438HIGHCVSS 7.5EG 7.52024-11-07
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
- CVE-2024-37277HIGHCVSS 7.5EG 7.52024-11-01
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
- CVE-2024-51066HIGHCVSS 7.5EG 7.52024-10-31
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.
- CVE-2024-47047HIGHCVSS 7.5EG 7.52024-09-17
An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure Direct Object Reference (IDOR) in some configurations. An unauthenticated attac…
- CVE-2024-3306HIGHCVSS 7.5EG 7.52024-09-12
Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for And…
- CVE-2024-3305HIGHCVSS 7.5EG 7.52024-09-12
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data. This issue affects SoliClub: before 4.4.0 for iOS, before 5.2.1 for Android.
- CVE-2024-1744HIGHCVSS 7.5EG 7.52024-09-06
Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data. This issue affects Accord ORS: before 7.3.2.1.
- CVE-2024-43315HIGHCVSS 7.5EG 7.52024-08-18
Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.
- CVE-2024-39321HIGHCVSS 7.5EG 7.52024-07-05
Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addre…
- CVE-2024-5130HIGHCVSS 7.5EG 7.52024-06-06
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due to the lack of proper authorization checks in the da…
- CVE-2024-33818HIGHCVSS 7.5EG 7.52024-05-14
Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.
- CVE-2024-4538HIGHCVSS 7.5EG 7.52024-05-07
IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain a user's event ticket by creating a specific request with the ticket reference ID, leading to the exposure of s…
- CVE-2024-4537HIGHCVSS 7.5EG 7.52024-05-07
IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to obtain the purchased ticket.
- CVE-2024-24312HIGHCVSS 7.5EG 7.52024-05-01
SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserModel.php component.
- CVE-2024-33383HIGHCVSS 7.5EG 7.52024-04-30
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.
- CVE-2024-27630HIGHCVSS 7.5EG 7.52024-04-08
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.
- CVE-2024-22305HIGHCVSS 7.5EG 7.52024-01-31
Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a …
- CVE-2024-23747HIGHCVSS 7.5EG 7.52024-01-29
The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO…
- CVE-2023-45893HIGHCVSS 7.5EG 7.52024-01-02
An indirect Object Reference (IDOR) in the Order and Invoice pages in Floorsight Customer Portal Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.
- CVE-2023-45892HIGHCVSS 7.5EG 7.52024-01-02
An issue discovered in the Order and Invoice pages in Floorsight Insights Q3 2023 allows an unauthenticated remote attacker to view sensitive customer information.
- CVE-2023-51503HIGHCVSS 7.5EG 7.52023-12-31
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from…
- CVE-2023-35916HIGHCVSS 7.5EG 7.52023-12-20
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This issue affects WooPayments – Fully Integrated Solution Built and Supported by Woo: from…
- CVE-2023-35914HIGHCVSS 7.5EG 7.52023-12-20
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a through 5.1.2.
- CVE-2023-49812HIGHCVSS 7.5EG 7.52023-12-19
Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
- CVE-2023-49298HIGHCVSS 7.5EG 7.52023-11-24
OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanis…
- CVE-2023-38884HIGHCVSS 7.5EG 7.52023-11-20
An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote attacker to access any student's files by visiting '/assets/studentfiles/<studentId>-<filenam…
- CVE-2022-24400HIGHCVSS 7.5EG 7.52023-10-19
A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.
- CVE-2023-32078HIGHCVSS 7.5EG 7.52023-08-24
Netmaker makes networks with WireGuard. An Insecure Direct Object Reference (IDOR) vulnerability was found in versions prior to 0.17.1 and 0.18.6 in the user update function. By specifying another user's username, it was possible to update…
- CVE-2023-37543HIGHCVSS 7.5EG 7.52023-08-10
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →