CWE-639— Authorization Bypass Through User-Controlled Key (IDOR)
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.— MITRE CWE catalog
2,981 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-639page 8 of 60
- CVE-2025-46386HIGHCVSS 8.8EG 8.82025-08-06
CWE-639 Authorization Bypass Through User-Controlled Key
- CVE-2025-51865HIGHCVSS 8.8EG 8.82025-07-22
Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.
- CVE-2025-6765HIGHCVSS 8.8EG 8.82025-06-27
A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of the component HTTP PUT Request Handler. The manipulation leads to p…
- CVE-2025-3610HIGHCVSS 8.8EG 8.82025-05-06
The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.1.2. This is due to the plugin not properly validating a user's identity prior to updating their det…
- CVE-2025-2526HIGHCVSS 8.8EG 8.82025-04-08
The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details li…
- CVE-2024-8613HIGHCVSS 8.8EG 8.82025-03-20
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enab…
- CVE-2024-12048HIGHCVSS 8.8EG 8.82025-03-20
An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete …
- CVE-2025-1667HIGHCVSS 8.8EG 8.82025-03-15
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wpsp_UpdateTeacher() function in all versions up to, and including, 2.2.16. This makes it po…
- CVE-2024-53406HIGHCVSS 8.8EG 8.82025-03-13
Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection phase, the device reuses the session key from a previous connection session, creating an opportunity for attackers to ex…
- CVE-2024-34520HIGHCVSS 8.8EG 8.82025-02-12
An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing th…
- CVE-2024-10497HIGHCVSS 8.8EG 8.82025-01-17
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of Privileges) when the attacker sends modified HT…
- CVE-2024-13040HIGHCVSS 8.8EG 8.82024-12-31
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any u…
- CVE-2024-55506HIGHCVSS 8.8EG 8.82024-12-18
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.
- CVE-2024-50395HIGHCVSS 8.8EG 8.82024-11-22
An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnera…
- CVE-2024-48217HIGHCVSS 8.8EG 8.82024-11-01
An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.
- CVE-2024-9637HIGHCVSS 8.8EG 8.82024-10-26
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identit…
- CVE-2024-9215HIGHCVSS 8.8EG 8.82024-10-17
The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and includ…
- CVE-2024-9687HIGHCVSS 8.8EG 8.82024-10-15
The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-controlled key on the 'validate_tg' action. This makes it possib…
- CVE-2024-8290HIGHCVSS 8.8EG 8.82024-09-25
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.12 via the WCFM_Customers_M…
- CVE-2024-8428HIGHCVSS 8.8EG 8.82024-09-06
The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validati…
- CVE-2024-32166HIGHCVSS 8.8EG 8.82024-04-19
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).
- CVE-2023-6523HIGHCVSS 8.8EG 8.82024-04-05
Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse. This issue affects Extreme XDS: before 3914.
- CVE-2023-6724HIGHCVSS 8.8EG 8.82024-02-09
Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse. This issue affects Hearing Tracking System: before f…
- CVE-2023-6515HIGHCVSS 8.8EG 8.82024-02-08
Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abuse. This issue affects MİA-MED: before 1.0.7.
- CVE-2023-49251HIGHCVSS 8.8EG 8.82024-01-09
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.7). The "intermediate installation" system state of the affected application allows an attacker to add their own login credentials to the device. This allows an atta…
- CVE-2023-48641HIGHCVSS 8.8EG 8.82023-12-12
Archer Platform 6.x before 6.14 P1 HF2 (6.14.0.1.2) contains an insecure direct object reference vulnerability. An authenticated malicious user in a multi-instance installation could potentially exploit this vulnerability by manipulating a…
- CVE-2023-45380HIGHCVSS 8.8EG 8.82023-11-07
In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, …
- CVE-2023-46478HIGHCVSS 8.8EG 8.82023-10-30
An issue in minCal v.1.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the customer_data parameter.
- CVE-2022-24401HIGHCVSS 8.8EG 8.82023-10-19
Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TDMA frame counters, which are frequently broadcast by the infrastructure in an unauthentica…
- CVE-2023-42455HIGHCVSS 8.8EG 8.82023-10-09
Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logg…
- CVE-2023-4934HIGHCVSS 8.8EG 8.82023-09-27
Authorization Bypass Through User-Controlled Key vulnerability in Usta AYBS allows Authentication Abuse, Authentication Bypass. This issue affects AYBS: before 1.0.3.
- CVE-2023-4213HIGHCVSS 8.8EG 8.82023-09-13
The Simplr Registration Form Plus+ plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.4.5. This is due to the plugin providing user-controlled access to objects, letting a user bypas…
- CVE-2020-10130HIGHCVSS 8.8EG 8.82023-09-06
SearchBlox before Version 9.1 is vulnerable to business logic bypass where the user is able to create multiple super admin users in the system.
- CVE-2023-28481HIGHCVSS 8.8EG 8.82023-08-14
An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SSH public key into the authorised keys file. This allows an …
- CVE-2023-3105HIGHCVSS 8.8EG 8.82023-07-12
The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization a…
- CVE-2022-42175HIGHCVSS 8.8EG 8.82023-07-05
Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker to change the password and hostname of other customer servers without authorization.
- CVE-2023-3063HIGHCVSS 8.8EG 8.82023-06-30
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass …
- CVE-2021-33223HIGHCVSS 8.8EG 8.82023-06-07
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.
- CVE-2023-0985HIGHCVSS 8.8EG 8.82023-06-06
An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any u…
- CVE-2023-2883HIGHCVSS 8.8EG 8.82023-05-25
Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
- CVE-2023-2065HIGHCVSS 8.8EG 8.82023-05-24
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass. This issue affects Cargo Tracking System: before 3558f28 .
- CVE-2023-2702HIGHCVSS 8.8EG 8.82023-05-23
Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition Management System allows Authentication Abuse, Authentication Bypass. This issue affects Competition Management System: before 23.07.
- CVE-2023-2260HIGHCVSS 8.8EG 8.82023-04-24
Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
- CVE-2023-1462HIGHCVSS 8.8EG 8.82023-03-21
Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentication Abuse. This issue affects DigiKent: before 23.03.20.
- CVE-2023-0865HIGHCVSS 8.8EG 8.82023-03-20
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allo…
- CVE-2023-0882HIGHCVSS 8.8EG 8.82023-02-17
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16.
- CVE-2022-45927HIGHCVSS 8.8EG 8.82023-01-18
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication of the QDS endpoints of the Content Server. These endpoints can be used to create objects …
- CVE-2022-4803HIGHCVSS 8.8EG 8.82022-12-28
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4505HIGHCVSS 8.8EG 8.82022-12-15
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.
- CVE-2022-2808HIGHCVSS 8.8EG 8.82022-12-02
Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection. This issue affects Prens Student Information System: before 2.1.11.
Map vulnerabilities like CWE-639 to your infrastructure
EchelonGraph correlates every CVE — across CWE-639 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →