CWE-288: CWE-288

237
Total CVEs
131
Critical
74
High
8.7
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
29
2025
117
2024
61
2023
11
2022
11

Top Affected Vendors

1 Pingidentity 6
2 Fortinet 5
3 Ibm 5
4 Miniorange 4
5 Jetbrains 4
6 Mozilla 4
7 Apache 4
8 Ivanti 4
9 Google 3
10 Automationdirect 3

All CWE-288 CVEs (237)

CVE-2026-20079
10.0

An authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to execute arbitrary s...

Mar 4, 2026
CVE-2024-11639
10.0

This critical vulnerability allows remote unauthenticated attackers to bypass authentication in Ivanti CSA's admin web console, granting them full adm...

Dec 10, 2024
CVE-2024-10081
10.0

CVE-2024-10081 is an authentication bypass vulnerability in CodeChecker that allows attackers to gain superuser access to all API endpoints except the...

Nov 6, 2024
CVE-2024-2973
10.0

This CVE-2024-2973 is an authentication bypass vulnerability affecting Juniper Networks Session Smart Router, Session Smart Conductor, and WAN Assuran...

Jun 27, 2024
CVE-2024-1709
10.0

CVE-2024-1709 is an authentication bypass vulnerability in ConnectWise ScreenConnect that allows attackers to access administrative functions without ...

Feb 21, 2024
CVE-2026-2628
9.8

The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress has an authentication bypass vulnerability that allows unauthenticat...

Mar 3, 2026
CVE-2025-69985
9.8

CVE-2025-69985 is an authentication bypass vulnerability in FUXA SCADA/HMI software that allows remote unauthenticated attackers to execute arbitrary ...

Feb 24, 2026
CVE-2026-2784
9.8

This CVE describes a DOM security component mitigation bypass vulnerability in Firefox. Attackers could potentially bypass security controls to execut...

Feb 24, 2026
CVE-2026-2096
9.8

Agentflow software by Flowring has a Missing Authentication vulnerability (CWE-288) that allows unauthenticated remote attackers to directly access da...

Feb 10, 2026
CVE-2026-2095
9.8

Agentflow software from Flowring contains an authentication bypass vulnerability that allows unauthenticated remote attackers to obtain arbitrary user...

Feb 10, 2026
CVE-2025-21589
9.8

This authentication bypass vulnerability in Juniper Session Smart products allows network-based attackers to gain administrative control without valid...

Jan 27, 2026
CVE-2026-24858
KEV 9.8

This authentication bypass vulnerability allows attackers with a FortiCloud account and registered device to log into other organizations' Fortinet de...

Jan 27, 2026
CVE-2025-69101
9.8

This vulnerability allows attackers to bypass authentication in the Workreap Core WordPress plugin, potentially gaining unauthorized access to user ac...

Jan 22, 2026
CVE-2026-23760
KEV EPSS 55.5% 9.8

CVE-2026-23760 is an authentication bypass vulnerability in SmarterMail's password reset API that allows unauthenticated attackers to reset administra...

Jan 22, 2026
CVE-2025-10484
9.8

This vulnerability allows unauthenticated attackers to bypass authentication in the Registration & Login with Mobile Phone Number for WooCommerce Word...

Jan 17, 2026
CVE-2025-67915
9.8

This CVE describes an authentication bypass vulnerability in the Arraytics Timetics WordPress plugin that allows attackers to gain unauthorized access...

Jan 8, 2026
CVE-2025-23504
9.8

This CVE describes an authentication bypass vulnerability in the RiceTheme Felan Framework WordPress plugin that allows attackers to gain unauthorized...

Jan 8, 2026
CVE-2025-64121
9.8

An authentication bypass vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows attackers to access protected functionality without vali...

Jan 2, 2026
CVE-2025-68860
9.8

This CVE describes an authentication bypass vulnerability in the Mobile Builder WordPress plugin that allows attackers to gain unauthorized access wit...

Dec 29, 2025
CVE-2025-64236
9.8

This CVE describes an authentication bypass vulnerability in the AmentoTech Tuturn WordPress plugin that allows attackers to gain unauthorized access ...

Dec 18, 2025
CVE-2025-13539
9.8

The FindAll Membership WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as administrative u...

Nov 27, 2025
CVE-2025-63217
9.8

This vulnerability allows attackers to bypass authentication on Itel DAB MUX devices by reusing a valid JWT token from one device to gain administrati...

Nov 18, 2025
CVE-2025-59367
9.8

This authentication bypass vulnerability in certain ASUS DSL series routers allows remote attackers to gain unauthorized administrative access without...

Nov 13, 2025
CVE-2025-64281
9.8

This critical authentication bypass vulnerability in CentralSquare Community Development allows attackers to access the admin panel without valid admi...

Nov 12, 2025
CVE-2025-62064
9.8

This CVE describes an authentication bypass vulnerability in the Search & Go WordPress theme that allows attackers to exploit password recovery mechan...

Nov 6, 2025
CVE-2025-5397
9.8

This vulnerability allows unauthenticated attackers to bypass authentication and gain administrative access to WordPress sites using the Noo JobMonste...

Oct 31, 2025
CVE-2025-49901
9.8

This vulnerability allows attackers to bypass authentication mechanisms in the quantumcloud Simple Link Directory WordPress plugin, potentially gainin...

Oct 22, 2025
CVE-2025-9967
9.8

The Orion SMS OTP Verification WordPress plugin allows unauthenticated attackers to reset any user's password if they know the victim's phone number. ...

Oct 15, 2025
CVE-2025-10294
9.8

The OwnID Passwordless Login plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any us...

Oct 15, 2025
CVE-2025-11522
9.8

This vulnerability allows unauthenticated attackers to bypass authentication and take over any user account, including administrator accounts, in Word...

Oct 9, 2025
CVE-2025-6388
9.8

The Spirit Framework WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, includin...

Oct 3, 2025
CVE-2025-8359
9.8

The AdForest WordPress theme contains an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, including ad...

Sep 6, 2025
CVE-2025-54738
9.8

This CVE describes an authentication bypass vulnerability in the NooTheme Jobmonster WordPress theme that allows attackers to gain unauthorized access...

Aug 28, 2025
CVE-2025-54725
9.8

This authentication bypass vulnerability in the Golo WordPress theme allows attackers to gain unauthorized access without valid credentials. It affect...

Aug 28, 2025
CVE-2025-34520
9.8

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to bypass login mechanisms and gain ...

Aug 27, 2025
CVE-2025-27129
9.8

An authentication bypass vulnerability in Tenda AC6 routers allows attackers to bypass HTTP authentication and execute arbitrary code. This affects Te...

Aug 20, 2025
CVE-2025-8995
9.8

This vulnerability allows attackers to bypass authentication in Drupal sites using the Authenticator Login module by exploiting an alternate path or c...

Aug 15, 2025
CVE-2025-51452
9.8

This vulnerability allows unauthenticated attackers to bypass login authentication on TOTOLINK A7000R routers by sending a specific request to formLog...

Aug 13, 2025
CVE-2025-53187
9.8

A debug configuration issue in ASPECT FW allows unauthenticated attackers to bypass authentication and perform unauthorized actions like changing syst...

Aug 11, 2025
CVE-2025-7710
9.8

The Brave Conversion Engine (PRO) WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any u...

Aug 2, 2025
CVE-2025-6895
9.8

The Melapress Login Security WordPress plugin versions 2.1.0 to 2.1.1 contain an authentication bypass vulnerability in the get_valid_user_based_on_to...

Jul 26, 2025
CVE-2025-7444
9.8

The LoginPress Pro WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user, i...

Jul 18, 2025
CVE-2025-30026
9.8

CVE-2025-30026 is an authentication bypass vulnerability in AXIS Camera Station Server that allows attackers to access the system without valid creden...

Jul 11, 2025
CVE-2025-6688
9.8

The Simple Payment WordPress plugin contains an authentication bypass vulnerability that allows unauthenticated attackers to log in as administrative ...

Jun 27, 2025
CVE-2025-51381
9.8

An authentication bypass vulnerability in KCM3100 firmware allows attackers on the same local network to gain unauthorized access without valid creden...

Jun 18, 2025
CVE-2025-4973
9.8

The Workreap WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any registered user, inclu...

Jun 12, 2025
CVE-2025-30184
9.8

CVE-2025-30184 allows unauthenticated attackers to bypass authentication and access the CyberData 011209 Intercom web interface through an alternate p...

Jun 9, 2025
CVE-2025-31022
9.8

This CVE describes an authentication bypass vulnerability in the PayU India WordPress plugin that allows attackers to gain unauthorized access to user...

Jun 9, 2025
CVE-2025-4797
9.8

This vulnerability allows unauthenticated attackers to log in as any WordPress user, including administrators, by exploiting improper identity validat...

Jun 3, 2025
CVE-2025-46412
9.8

This authentication bypass vulnerability in Vertiv products allows attackers to access webserver functions without proper credentials. Affected organi...

May 21, 2025

About CWE-288 (CWE-288)

Our database tracks 237 CVEs classified as CWE-288, with 131 rated critical and 74 rated high severity. The average CVSS score for CWE-288 vulnerabilities is 8.7.

External reference: View CWE-288 on MITRE CWE →

Monitor CWE-288 Vulnerabilities

Get alerted when new CWE-288 CVEs affect your infrastructure.

Start Monitoring Free