CWE-639: CWE-639
Yearly Trend
Top Affected Vendors
All CWE-639 CVEs (519)
This broken access control vulnerability allows authenticated attackers to modify any user's templates in lunary-ai/lunary by sending crafted HTTP POS...
Mar 20, 2025The Omnipress WordPress plugin vulnerability allows authenticated attackers with Contributor-level access or higher to view password-protected, privat...
Mar 14, 2025This vulnerability in SAP S/4HANA's Manage Bank Statements functionality allows authenticated users to bypass intended restrictions and upload files t...
Mar 11, 2025This vulnerability in SAP S/4HANA's Manage Bank Statements function allows authenticated users to delete attachments from posted bank statements witho...
Mar 11, 2025This vulnerability in the FooGallery WordPress plugin allows authenticated attackers with gallery creator access or higher to modify arbitrary posts a...
Mar 8, 2025The Ultra Addons Lite for Elementor WordPress plugin has an information exposure vulnerability that allows authenticated attackers with Contributor-le...
Feb 28, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete profile photos from other user accounts. It a...
Feb 22, 2025The DethemeKit For Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to duplicate password-protected, ...
Feb 13, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to export ticket data belonging to any user in the Maje...
Feb 12, 2025The Typer Core WordPress plugin has an information disclosure vulnerability that allows authenticated users with Contributor-level access or higher to...
Jan 30, 2025The Piotnet Addons For Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to extract data from private ...
Jan 15, 2025The RRAddons for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to view private or draft posts they...
Jan 11, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to submit resumes on behalf of other applicants when ap...
Jan 7, 2025This vulnerability in the WP Job Portal WordPress plugin allows authenticated users with Subscriber-level access or higher to create job listings for ...
Jan 3, 2025An Insecure Direct Object Reference (IDOR) vulnerability in Khoj's subscription endpoint allows authenticated users to modify other users' Stripe subs...
Dec 30, 2024The Full Screen Menu for Elementor WordPress plugin allows authenticated attackers with contributor-level access or higher to view private or draft po...
Dec 21, 2024An IDOR vulnerability in Oqtane Framework 6.0.0 allows authenticated users to access other users' inbox messages by manipulating notification IDs in U...
Dec 20, 2024The Shortcodes for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to extract data from private and ...
Dec 14, 2024The Get Post Content Shortcode WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Contrib...
Dec 14, 2024An object-level access control vulnerability in Unifiedtransform allows unauthorized students to view other students' grades by manipulating the stude...
Dec 9, 2024The PowerPack Elementor Addons WordPress plugin has an information exposure vulnerability that allows authenticated attackers with Contributor-level a...
Dec 6, 2024The AnyWhere Elementor WordPress plugin vulnerability allows authenticated attackers with Contributor-level access or higher to extract data from priv...
Dec 5, 2024The LA-Studio Element Kit for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to view private and dr...
Dec 4, 2024This vulnerability in the Dollie Hub WordPress plugin allows authenticated attackers with Contributor-level access or higher to view password-protecte...
Dec 4, 2024This vulnerability allows authenticated WordPress users with Contributor-level access or higher to extract data from private or draft posts created vi...
Nov 28, 2024The Primary Addon for Elementor WordPress plugin has an information exposure vulnerability that allows authenticated users with Contributor-level acce...
Nov 28, 2024The Easy Twitter Feed WordPress plugin has an information exposure vulnerability that allows authenticated users with Contributor-level access or high...
Nov 22, 2024This vulnerability in the If-So Dynamic Content Personalization WordPress plugin allows authenticated attackers with Contributor-level access or highe...
Nov 21, 2024This vulnerability allows authenticated WordPress users with Contributor-level access or higher to view draft, private, and pending posts they shouldn...
Nov 21, 2024The Theme Builder For Elementor WordPress plugin has an information exposure vulnerability that allows authenticated users with Contributor-level acce...
Nov 21, 2024The Popularis Extra WordPress plugin has an information disclosure vulnerability that allows authenticated attackers with Contributor-level access or ...
Nov 16, 2024This vulnerability in the WordPress Countdown Timer block plugin allows authenticated attackers with Contributor-level access or higher to bypass acce...
Nov 9, 2024This vulnerability allows authenticated data.all users to bypass intended access controls by manipulating dataset queries to retrieve sensitive enviro...
Nov 9, 2024This IDOR vulnerability in KubeSphere allows authenticated users with low privileges to access sensitive resources they shouldn't have permission to v...
Oct 14, 2024This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Mirapolis LMS that allows authenticated users to manipulate ID and STEP...
Sep 12, 2024This vulnerability allows authenticated WordPress users with subscriber-level access or higher to access other users' private files through the User P...
Aug 22, 2024This vulnerability allows attackers to bypass authorization by manipulating user-controlled keys, enabling unauthorized access to restricted resources...
Aug 18, 2024The Custom Field For WP Job Manager WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with co...
Aug 16, 2024This vulnerability allows attackers to bypass authorization controls in Academy LMS WordPress plugin by manipulating user-controlled keys. It affects ...
Jul 22, 2024The Page and Post Clone WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Author-level p...
Jun 29, 2024This vulnerability in the Bricks Builder WordPress plugin allows authenticated users with Contributor-level access or higher to modify posts and pages...
Jun 22, 2024The User Profile Picture WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Author-level ...
Jun 21, 2024This vulnerability allows authenticated attackers with Instructor-level access or higher in Tutor LMS WordPress plugin to delete arbitrary quiz attemp...
Jun 7, 2024This vulnerability in McAfee ePolicy Orchestrator (ePO) allows authenticated users with regular privileges to delete client tasks and assignments thro...
May 16, 2024Chainlit versions before 2.8.5 contain an authorization bypass vulnerability where attackers can view threads or claim thread ownership by manipulatin...
Jan 14, 2026HCL Unica Centralized Offer Management has an Insecure Direct Object Reference (IDOR) vulnerability that allows attackers to bypass authorization and ...
Oct 12, 2025This vulnerability in OpenSearch Observability plugins allows unauthorized users to access private tenant resources like notebooks. It affects OpenSea...
Jul 9, 2024This vulnerability allows authenticated users to view certain pipeline values via API queries in affected GitLab versions. It affects all GitLab CE/EE...
Feb 11, 2026This vulnerability in Nextcloud Talk allows participants with chat permissions to delete poll drafts created by other participants within the same con...
Dec 5, 2025This vulnerability in Nextcloud Calendar allows attackers to blindly book appointments using sequential IDs without needing the appointment token. It ...
Dec 5, 2025About CWE-639 (CWE-639)
Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.
External reference: View CWE-639 on MITRE CWE →
Monitor CWE-639 Vulnerabilities
Get alerted when new CWE-639 CVEs affect your infrastructure.
Start Monitoring Free