CWE-942— Permissive Cross-domain Policy with Untrusted Domains
38 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-942page 1 of 1
- CVE-2019-14860MEDIUMCVSS 6.5EG 6.52019-11-08
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
- CVE-2020-36851CRITICALCVSS 9.5EG 0.02025-09-25
Rob--W cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to make HTTP requests to arbitrary targets (SSRF). Because the proxy forwards requests and headers, an attacker can reach …
- CVE-2021-27786MEDIUMCVSS 4.6EG 9.82022-06-09
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between…
- CVE-2021-34435HIGHCVSS 8.8EG 8.82021-09-01
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happen…
- CVE-2022-22808HIGHCVSS 8.8EG 8.82022-02-09
A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections by…
- CVE-2022-26969CRITICALCVSS 9.8EG 9.82022-12-26
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
- CVE-2022-31736CRITICALCVSS 9.8EG 9.82022-12-22
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
- CVE-2022-34366MEDIUMCVSS 6.5EG 6.52023-02-10
Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.
- CVE-2022-47717HIGHCVSS 7.5EG 7.52023-02-01
Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
- CVE-2023-23128MEDIUMCVSS 6.1EG 6.12023-02-01
Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk…
- CVE-2023-23464HIGHCVSS 8.1EG 7.52023-02-15
Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.
- CVE-2023-2360HIGHCVSS 7.5EG 3.12023-04-28
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.
- CVE-2023-25603MEDIUMCVSS 5.4EG 5.42023-11-14
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive inf…
- CVE-2023-36829MEDIUMCVSS 6.8EG 6.82023-07-06
Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly returns the `access-control-allow-credentials: true` HTTP header if the `Origin` request he…
- CVE-2023-37526MEDIUMCVSS 6.5EG 6.52024-05-14
HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any …
- CVE-2023-38122HIGHCVSS 7.2EG 7.22024-05-03
Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ig…
- CVE-2023-38125HIGHCVSS 8.8EG 7.52024-05-03
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Aut…
- CVE-2023-45213MEDIUMCVSS 6.6EG 6.62024-02-06
A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the device.
- CVE-2023-46098HIGHCVSS 8.0EG 8.02023-11-14
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, the products use an overly permissive CORS policy. This could allow an attacker to trick a legitima…
- CVE-2023-46281HIGHCVSS 7.1EG 7.12023-12-12
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation…
- CVE-2023-50940MEDIUMCVSS 5.3EG 5.32024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM …
- CVE-2024-10315MEDIUMCVSS 6.9EG 0.02024-11-11
In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.
- CVE-2024-21382MEDIUMCVSS 4.3EG 4.32024-01-26
Microsoft Edge for Android Information Disclosure Vulnerability
- CVE-2024-23823MEDIUMCVSS 4.2EG 4.22024-03-14
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for…
- CVE-2024-25124CRITICALCVSS 9.4EG 9.42024-02-21
Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting…
- CVE-2024-32862MEDIUMCVSS 6.8EG 6.82024-08-01
Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.
- CVE-2024-37131HIGHCVSS 7.5EG 7.52024-06-13
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious action…
- CVE-2024-41657HIGHCVSS 8.1EG 8.12024-08-20
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests t…
- CVE-2024-41659HIGHCVSS 8.1EG 8.12024-08-20
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking web…
- CVE-2024-45642MEDIUMCVSS 5.3EG 5.32024-11-14
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo…
- CVE-2024-49763HIGHCVSS 8.7EG 0.02024-12-02
PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking websit…
- CVE-2024-53276MEDIUMCVSS 6.3EG 0.02024-12-23
Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, an open CORS policy in app.js may allow an attacker to view the images of home-gallery when it is using the default sett…
- CVE-2024-6449MEDIUMCVSS 6.5EG 6.52024-08-28
HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon ope…
- CVE-2026-44895CRITICALCVSS 9.2EG 9.22026-05-26
GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin: * on every response. The structural de…
- CVE-2026-46431MEDIUMCVSS 4.3EG 4.32026-05-20
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless of the caller's Origin. Because EventSource does not pref…
- CVE-2026-8537MEDIUMCVSS 4.3EG 4.32026-05-14
Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-8576MEDIUMCVSS 4.3EG 4.32026-05-14
Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-8948CRITICALCVSS 9.1EG 9.12026-05-19
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
Map vulnerabilities like CWE-942 to your infrastructure
EchelonGraph correlates every CVE — across CWE-942 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →