The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Volume of CVEs assigned to CWE-639 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
2,063 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6875CRITICAL The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification | Jan 11, 2024 | 9.8 | 90 | NO | YES |
CVE-2026-55255HIGH Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoin | Jun 23, 2026 | 8.4 | 81 | YES | NO |
CVE-2021-45428CRITICAL TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats. | Jan 3, 2022 | 9.8 | 80 | NO | YES |
CVE-2019-17382CRITICAL An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then creat | Oct 9, 2019 | 9.1 | 69 | NO | YES |
CVE-2024-46982HIGH Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered r | Sep 17, 2024 | 7.5 | 59 | NO | NO |
CVE-2019-13360CRITICAL In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username. | Jul 16, 2019 | 9.8 | 55 | NO | YES |
CVE-2025-5947CRITICAL The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugi | Aug 1, 2025 | 9.8 | 53 | NO | YES |
CVE-2025-3605CRITICAL The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due | May 9, 2025 | 9.8 | 51 | NO | YES |
CVE-2022-22832CRITICAL An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request. | Feb 6, 2022 | 9.8 | 50 | NO | YES |
CVE-2026-8679HIGH The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() funct | May 22, 2026 | 7.5 | 46 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.