CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,978 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 2 of 60
- CVE-2026-44083CRITICALCVSS 9.8EG 9.82026-06-09
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the f…
- CVE-2026-2347CRITICALCVSS 9.8EG 9.82026-05-14
Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001.
- CVE-2026-24178CRITICALCVSS 9.8EG 9.82026-04-28
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may…
- CVE-2018-25270CRITICALCVSS 9.8EG 9.82026-04-22
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint …
- CVE-2026-2414CRITICALCVSS 9.8EG 9.82026-03-25
Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.5.2 before 10.7.2.
- CVE-2026-33511CRITICALCVSS 9.8EG 9.82026-03-24
pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host hea…
- CVE-2026-32867CRITICALCVSS 9.8EG 9.82026-03-19
OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users would see these unexpected files in cases. U…
- CVE-2017-20223CRITICALCVSS 9.8EG 9.82026-03-16
Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attack…
- CVE-2026-31874CRITICALCVSS 9.8EG 9.82026-03-11
Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate or restrict the role parameter during the user registration process. An attacker…
- CVE-2019-25487CRITICALCVSS 9.8EG 9.82026-03-11
SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests …
- CVE-2025-7013CRITICALCVSS 9.8EG 9.82026-01-29
Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifiers. This issue affects Menu Panel: through 29012026. NOTE: The vendor was contacted ear…
- CVE-2025-15521CRITICALCVSS 9.8EG 9.82026-01-21
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly va…
- CVE-2026-23478CRITICALCVSS 9.8EG 9.82026-01-13
Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email ad…
- CVE-2026-22234CRITICALCVSS 9.8EG 9.82026-01-08
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new fil…
- CVE-2025-15018CRITICALCVSS 9.8EG 9.82026-01-07
The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration context…
- CVE-2020-36923CRITICALCVSS 9.8EG 9.82026-01-06
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating cl…
- CVE-2025-15001CRITICALCVSS 9.8EG 9.82026-01-06
The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating…
- CVE-2025-14996CRITICALCVSS 9.8EG 9.82026-01-06
The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's iden…
- CVE-2025-14998CRITICALCVSS 9.8EG 9.82026-01-02
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. …
- CVE-2019-25235CRITICALCVSS 9.8EG 9.82025-12-24
Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to…
- CVE-2023-53955CRITICALCVSS 9.8EG 9.82025-12-22
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-su…
- CVE-2023-53914CRITICALCVSS 9.8EG 9.82025-12-17
UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpo…
- CVE-2025-67165CRITICALCVSS 9.8EG 9.82025-12-17
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
- CVE-2025-13615CRITICALCVSS 9.8EG 9.82025-11-30
The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and…
- CVE-2025-58627CRITICALCVSS 9.8EG 9.82025-11-06
Authorization Bypass Through User-Controlled Key vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous Core Plugin: from n/…
- CVE-2025-10742CRITICALCVSS 9.8EG 9.82025-10-16
The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization an…
- CVE-2025-5948CRITICALCVSS 9.8EG 9.82025-09-19
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a …
- CVE-2025-9114CRITICALCVSS 9.8EG 9.82025-09-08
The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access …
- CVE-2025-45968CRITICALCVSS 9.8EG 9.82025-08-25
An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Insecure Direct Object Reference (IDOR) vulnerability, which occurs due to a lack of proper a…
- CVE-2025-5947CRITICALCVSS 9.8EG 9.82025-08-01
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to lo…
- CVE-2025-4855CRITICALCVSS 9.8EG 9.82025-07-09
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it po…
- CVE-2025-3605CRITICALCVSS 9.8EG 9.82025-05-09
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity pri…
- CVE-2025-3811CRITICALCVSS 9.8EG 9.82025-05-09
The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details l…
- CVE-2025-3810CRITICALCVSS 9.8EG 9.82025-05-09
The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details l…
- CVE-2024-11285CRITICALCVSS 9.8EG 9.82025-03-14
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 7.1. This is due to the plugin not properly validating a user's identity prior to updating their details l…
- CVE-2024-11284CRITICALCVSS 9.8EG 9.82025-03-14
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.9. This is due to the plugin not properly validating a user's identity prior to updating their password …
- CVE-2024-8261CRITICALCVSS 9.8EG 9.82025-03-03
Authorization Bypass Through User-Controlled Key vulnerability in Proliz Software OBS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects OBS: before 24.0927.
- CVE-2024-10215CRITICALCVSS 9.8EG 9.82025-01-09
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and acces…
- CVE-2024-50483CRITICALCVSS 9.8EG 9.82024-10-28
Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.
- CVE-2024-9263CRITICALCVSS 9.8EG 9.82024-10-17
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.…
- CVE-2024-9862CRITICALCVSS 9.8EG 9.82024-10-17
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a us…
- CVE-2024-8485CRITICALCVSS 9.8EG 9.82024-09-25
The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key t…
- CVE-2024-8791CRITICALCVSS 9.8EG 9.82024-09-24
The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly ve…
- CVE-2024-27113CRITICALCVSS 9.8EG 9.82024-09-11
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlyin…
- CVE-2024-8292CRITICALCVSS 9.8EG 9.82024-09-06
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plugin not properly verifying a user's id…
- CVE-2024-27730CRITICALCVSS 9.8EG 9.82024-08-15
Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.
- CVE-2024-39223CRITICALCVSS 9.8EG 9.82024-07-03
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
- CVE-2024-1107CRITICALCVSS 9.8EG 9.82024-06-27
Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Travel APPS: before v17.0.68.
- CVE-2023-6875CRITICALCVSS 9.8EG 9.82024-01-11
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app …
- CVE-2024-0264CRITICALCVSS 9.8EG 9.82024-01-07
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. The manipulation of the argument formToken leads to author…
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →