CWE-288: CWE-288

235
Total CVEs
130
Critical
73
High
8.7
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
29
2025
117
2024
61
2023
11
2022
11

Top Affected Vendors

1 Pingidentity 6
2 Fortinet 5
3 Ibm 5
4 Jetbrains 4
5 Mozilla 4
6 Apache 4
7 Ivanti 4
8 Miniorange 4
9 Automationdirect 3
10 Google 3

All CWE-288 CVEs (235)

CVE-2025-22462
9.8

An authentication bypass vulnerability in Ivanti Neurons for ITSM on-premises deployments allows remote unauthenticated attackers to gain administrati...

May 13, 2025
CVE-2025-3844
9.8

The PeproDev Ultimate Profile Solutions WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as...

May 7, 2025
CVE-2025-1909
9.8

The BuddyBoss Platform Pro WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing...

May 5, 2025
CVE-2024-13553
9.8

This vulnerability allows unauthenticated attackers to bypass authentication and take over any user account, including administrators, in the SMS Aler...

Apr 1, 2025
CVE-2025-31095
9.8

CVE-2025-31095 is an authentication bypass vulnerability in the Material Dashboard WordPress plugin that allows attackers to gain unauthorized access ...

Apr 1, 2025
CVE-2025-2746
KEV EPSS 87.4% 9.8

An authentication bypass vulnerability in Kentico Xperience's Staging Sync Server allows attackers to bypass digest authentication by exploiting empty...

Mar 24, 2025
CVE-2024-13442
9.8

This vulnerability allows unauthenticated attackers to take over any user account, including administrators, in WordPress sites using the Service Find...

Mar 19, 2025
CVE-2024-13771
9.8

This vulnerability allows unauthenticated attackers to reset passwords for any user account in the Civi WordPress theme, including administrators, by ...

Mar 14, 2025
CVE-2024-11286
9.8

The WP JobHunt plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log into any user account, inc...

Mar 14, 2025
CVE-2024-13446
9.8

The Workreap WordPress plugin allows unauthenticated attackers to take over any user account, including administrators, by exploiting insufficient ide...

Mar 12, 2025
CVE-2025-1315
9.8

The InWave Jobs WordPress plugin has a privilege escalation vulnerability that allows unauthenticated attackers to reset passwords of any user, includ...

Mar 7, 2025
CVE-2025-1515
9.8

The WP Real Estate Manager WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, in...

Mar 5, 2025
CVE-2025-1564
9.8

The SetSail Membership plugin for WordPress has an authentication bypass vulnerability in social login functionality. Unauthenticated attackers can lo...

Mar 1, 2025
CVE-2025-1671
9.8

The Academist Membership WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, incl...

Mar 1, 2025
CVE-2025-26966
9.8

This vulnerability allows unauthenticated attackers to bypass authentication in the PrivateContent WordPress plugin, potentially gaining administrativ...

Feb 25, 2025
CVE-2025-1283
9.8

This vulnerability allows attackers to bypass authentication on Dingtian DT-R0 Series devices by directly accessing the main page without valid creden...

Feb 13, 2025
CVE-2024-13182
9.8

The WP Directorybox Manager WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existin...

Feb 13, 2025
CVE-2025-0316
9.8

The WP Directorybox Manager plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any exi...

Feb 8, 2025
CVE-2025-1061
9.8

The Nextend Social Login Pro WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existi...

Feb 7, 2025
CVE-2025-0674
EPSS 45% 9.8

CVE-2025-0674 is an authentication bypass vulnerability affecting multiple Elber products that allows attackers to reset any user's password without a...

Feb 7, 2025
CVE-2025-0364
EPSS 25.6% 9.8

BigAntSoft BigAnt Server up to version 5.6.06 allows unauthenticated remote attackers to create administrative accounts through the default SaaS regis...

Feb 4, 2025
CVE-2024-12857
9.8

The AdForest WordPress theme has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user when OTP phone log...

Jan 22, 2025
CVE-2024-55591
KEV EPSS 94.2% 9.8

This vulnerability allows remote attackers to bypass authentication and gain super-admin privileges on affected Fortinet devices by sending crafted re...

Jan 14, 2025
CVE-2024-12402
9.8

This vulnerability allows unauthenticated attackers to change any WordPress user's password, including administrators, through the Themes Coder plugin...

Jan 7, 2025
CVE-2024-56044
9.8

CVE-2024-56044 is an authentication bypass vulnerability in the WPLMS WordPress plugin that allows unauthenticated attackers to generate arbitrary use...

Dec 31, 2024
CVE-2024-11349
9.8

The AdForest WordPress theme contains an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, including ad...

Dec 21, 2024
CVE-2024-43234
9.8

This vulnerability allows unauthenticated attackers to bypass authentication mechanisms in the Woffice WordPress theme, potentially gaining administra...

Dec 16, 2024
CVE-2024-54294
9.8

This CVE describes an authentication bypass vulnerability in the Firebase OTP Authentication WordPress plugin by AppGenixInfotech. Attackers can bypas...

Dec 13, 2024
CVE-2024-54296
9.8

This CVE describes an authentication bypass vulnerability in Codexpert's CoSchool LMS WordPress plugin that allows attackers to gain unauthorized acce...

Dec 13, 2024
CVE-2024-11925
9.8

The JobSearch WP Job Board WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user by ...

Nov 28, 2024
CVE-2024-10961
9.8

The Social Login WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user, inc...

Nov 23, 2024
CVE-2024-11028
9.8

This vulnerability allows unauthenticated attackers to bypass authentication in the MultiManager WP WordPress plugin by generating impersonation links...

Nov 13, 2024
CVE-2024-10245
9.8

The Relais 2FA plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user, i...

Nov 12, 2024
CVE-2024-10284
9.8

The CE21 Suite WordPress plugin up to version 2.2.0 contains a hardcoded encryption key that allows unauthenticated attackers to bypass authentication...

Nov 9, 2024
CVE-2024-50503
9.8

This authentication bypass vulnerability in the Deryck OΓ±ate User Toolkit WordPress plugin allows attackers to gain unauthorized access to user accou...

Oct 30, 2024
CVE-2024-9988
9.8

The Crypto plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user by exp...

Oct 29, 2024
CVE-2024-50477
9.8

This CVE describes an authentication bypass vulnerability in the Stacks Mobile App Builder WordPress plugin that allows attackers to gain unauthorized...

Oct 28, 2024
CVE-2024-50487
9.8

This CVE describes an authentication bypass vulnerability in the MaanStore API WordPress plugin that allows attackers to gain unauthorized access with...

Oct 28, 2024
CVE-2024-9501
9.8

The Wp Social Login and Register Social Counter WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to l...

Oct 26, 2024
CVE-2024-9930
9.8

This vulnerability allows unauthenticated attackers to bypass authentication in the Extensions by HocWP Team WordPress plugin. Attackers can log in as...

Oct 26, 2024
CVE-2024-10381
9.8

This vulnerability allows remote attackers to bypass authentication on Matrix Door Controller Cosec Vega FAXQ devices through improper session managem...

Oct 25, 2024
CVE-2024-9488
9.8

The wpDiscuz WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user, includi...

Oct 25, 2024
CVE-2024-49604
9.8

This vulnerability allows attackers to bypass authentication in the Simple User Registration WordPress plugin, potentially gaining unauthorized access...

Oct 20, 2024
CVE-2024-49328
9.8

This vulnerability allows attackers to bypass authentication in the WP REST API FNS WordPress plugin, potentially gaining unauthorized access to admin...

Oct 20, 2024
CVE-2024-9893
9.8

The Nextend Social Login Pro WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existi...

Oct 16, 2024
CVE-2024-9105
9.8

The UltimateAI WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing user by exp...

Oct 16, 2024
CVE-2024-9822
9.8

The Pedalo Connector WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as the first user (ty...

Oct 11, 2024
CVE-2024-9106
9.8

The Wechat Social login plugin for WordPress versions up to 1.3.0 contains an authentication bypass vulnerability that allows unauthenticated attacker...

Oct 1, 2024
CVE-2024-7503
9.8

The WooCommerce Social Login plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any ex...

Aug 12, 2024
CVE-2024-7350
9.8

The BookingPress WordPress plugin versions 1.1.6 to 1.1.7 contain an authentication bypass vulnerability that allows unauthenticated attackers to log ...

Aug 8, 2024

About CWE-288 (CWE-288)

Our database tracks 235 CVEs classified as CWE-288, with 130 rated critical and 73 rated high severity. The average CVSS score for CWE-288 vulnerabilities is 8.7.

External reference: View CWE-288 on MITRE CWE →

Monitor CWE-288 Vulnerabilities

Get alerted when new CWE-288 CVEs affect your infrastructure.

Start Monitoring Free