CWE-639: CWE-639

519
Total CVEs
63
Critical
165
High
6.6
Avg CVSS

Yearly Trend

2026
89
2025
239
2024
130
2023
28
2022
16

Top Affected Vendors

1 Growatt 12
2 Nextcloud 10
3 Easyappointments 8
4 Liferay 8
5 Boldworkplanner 8
6 Lunary 6
7 Gitlab 6
8 Open Emr 5
9 Wpjobportal 5
10 Apache 4

All CWE-639 CVEs (519)

CVE-2024-7476
4.3

This broken access control vulnerability allows authenticated attackers to modify any user's templates in lunary-ai/lunary by sending crafted HTTP POS...

Mar 20, 2025
CVE-2024-13407
4.3

The Omnipress WordPress plugin vulnerability allows authenticated attackers with Contributor-level access or higher to view password-protected, privat...

Mar 14, 2025
CVE-2025-27433
4.3

This vulnerability in SAP S/4HANA's Manage Bank Statements functionality allows authenticated users to bypass intended restrictions and upload files t...

Mar 11, 2025
CVE-2025-27436
4.3

This vulnerability in SAP S/4HANA's Manage Bank Statements function allows authenticated users to delete attachments from posted bank statements witho...

Mar 11, 2025
CVE-2024-12114
4.3

This vulnerability in the FooGallery WordPress plugin allows authenticated attackers with gallery creator access or higher to modify arbitrary posts a...

Mar 8, 2025
CVE-2024-13832
4.3

The Ultra Addons Lite for Elementor WordPress plugin has an information exposure vulnerability that allows authenticated attackers with Contributor-le...

Feb 28, 2025
CVE-2024-13873
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete profile photos from other user accounts. It a...

Feb 22, 2025
CVE-2025-0661
4.3

The DethemeKit For Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to duplicate password-protected, ...

Feb 13, 2025
CVE-2024-13601
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to export ticket data belonging to any user in the Maje...

Feb 12, 2025
CVE-2024-12102
4.3

The Typer Core WordPress plugin has an information disclosure vulnerability that allows authenticated users with Contributor-level access or higher to...

Jan 30, 2025
CVE-2024-10775
4.3

The Piotnet Addons For Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to extract data from private ...

Jan 15, 2025
CVE-2024-11915
4.3

The RRAddons for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to view private or draft posts they...

Jan 11, 2025
CVE-2024-12131
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to submit resumes on behalf of other applicants when ap...

Jan 7, 2025
CVE-2024-12132
4.3

This vulnerability in the WP Job Portal WordPress plugin allows authenticated users with Subscriber-level access or higher to create job listings for ...

Jan 3, 2025
CVE-2024-52294
4.3

An Insecure Direct Object Reference (IDOR) vulnerability in Khoj's subscription endpoint allows authenticated users to modify other users' Stripe subs...

Dec 30, 2024
CVE-2024-10797
4.3

The Full Screen Menu for Elementor WordPress plugin allows authenticated attackers with contributor-level access or higher to view private or draft po...

Dec 21, 2024
CVE-2024-55186
4.3

An IDOR vulnerability in Oqtane Framework 6.0.0 allows authenticated users to access other users' inbox messages by manipulating notification IDs in U...

Dec 20, 2024
CVE-2024-10690
4.3

The Shortcodes for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to extract data from private and ...

Dec 14, 2024
CVE-2024-12447
4.3

The Get Post Content Shortcode WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Contrib...

Dec 14, 2024
CVE-2024-12305
4.3

An object-level access control vulnerability in Unifiedtransform allows unauthorized students to view other students' grades by manipulating the stude...

Dec 9, 2024
CVE-2024-10692
4.3

The PowerPack Elementor Addons WordPress plugin has an information exposure vulnerability that allows authenticated attackers with Contributor-level a...

Dec 6, 2024
CVE-2024-10777
4.3

The AnyWhere Elementor WordPress plugin vulnerability allows authenticated attackers with Contributor-level access or higher to extract data from priv...

Dec 5, 2024
CVE-2024-10787
4.3

The LA-Studio Element Kit for Elementor WordPress plugin allows authenticated attackers with Contributor-level access or higher to view private and dr...

Dec 4, 2024
CVE-2024-12099
4.3

This vulnerability in the Dollie Hub WordPress plugin allows authenticated attackers with Contributor-level access or higher to view password-protecte...

Dec 4, 2024
CVE-2024-10798
4.3

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to extract data from private or draft posts created vi...

Nov 28, 2024
CVE-2024-10670
4.3

The Primary Addon for Elementor WordPress plugin has an information exposure vulnerability that allows authenticated users with Contributor-level acce...

Nov 28, 2024
CVE-2024-10666
4.3

The Easy Twitter Feed WordPress plugin has an information exposure vulnerability that allows authenticated users with Contributor-level access or high...

Nov 22, 2024
CVE-2024-10796
4.3

This vulnerability in the If-So Dynamic Content Personalization WordPress plugin allows authenticated attackers with Contributor-level access or highe...

Nov 21, 2024
CVE-2024-10696
4.3

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to view draft, private, and pending posts they shouldn...

Nov 21, 2024
CVE-2024-10782
4.3

The Theme Builder For Elementor WordPress plugin has an information exposure vulnerability that allows authenticated users with Contributor-level acce...

Nov 21, 2024
CVE-2024-10795
4.3

The Popularis Extra WordPress plugin has an information disclosure vulnerability that allows authenticated attackers with Contributor-level access or ...

Nov 16, 2024
CVE-2024-10669
4.3

This vulnerability in the WordPress Countdown Timer block plugin allows authenticated attackers with Contributor-level access or higher to bypass acce...

Nov 9, 2024
CVE-2024-52313
4.3

This vulnerability allows authenticated data.all users to bypass intended access controls by manipulating dataset queries to retrieve sensitive enviro...

Nov 9, 2024
CVE-2024-46528
4.3

This IDOR vulnerability in KubeSphere allows authenticated users with low privileges to access sensitive resources they shouldn't have permission to v...

Oct 14, 2024
CVE-2024-25270
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Mirapolis LMS that allows authenticated users to manipulate ID and STEP...

Sep 12, 2024
CVE-2024-7848
4.3

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to access other users' private files through the User P...

Aug 22, 2024
CVE-2024-43239
4.3

This vulnerability allows attackers to bypass authorization by manipulating user-controlled keys, enabling unauthorized access to restricted resources...

Aug 18, 2024
CVE-2023-7049
4.3

The Custom Field For WP Job Manager WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with co...

Aug 16, 2024
CVE-2024-38701
4.3

This vulnerability allows attackers to bypass authorization controls in Academy LMS WordPress plugin by manipulating user-controlled keys. It affects ...

Jul 22, 2024
CVE-2024-5942
4.3

The Page and Post Clone WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Author-level p...

Jun 29, 2024
CVE-2024-4874
4.3

This vulnerability in the Bricks Builder WordPress plugin allows authenticated users with Contributor-level access or higher to modify posts and pages...

Jun 22, 2024
CVE-2024-5639
4.3

The User Profile Picture WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Author-level ...

Jun 21, 2024
CVE-2024-5438
4.3

This vulnerability allows authenticated attackers with Instructor-level access or higher in Tutor LMS WordPress plugin to delete arbitrary quiz attemp...

Jun 7, 2024
CVE-2024-4843
4.3

This vulnerability in McAfee ePolicy Orchestrator (ePO) allows authenticated users with regular privileges to delete client tasks and assignments thro...

May 16, 2024
CVE-2025-68492
4.2

Chainlit versions before 2.8.5 contain an authorization bypass vulnerability where attackers can view threads or claim thread ownership by manipulatin...

Jan 14, 2026
CVE-2025-31997
4.2

HCL Unica Centralized Offer Management has an Insecure Direct Object Reference (IDOR) vulnerability that allows attackers to bypass authorization and ...

Oct 12, 2025
CVE-2024-39901
4.2

This vulnerability in OpenSearch Observability plugins allows unauthorized users to access private tenant resources like notebooks. It affects OpenSea...

Jul 9, 2024
CVE-2025-14594
3.5

This vulnerability allows authenticated users to view certain pipeline values via API queries in affected GitLab versions. It affects all GitLab CE/EE...

Feb 11, 2026
CVE-2025-66556
3.5

This vulnerability in Nextcloud Talk allows participants with chat permissions to delete poll drafts created by other participants within the same con...

Dec 5, 2025
CVE-2025-66546
3.3

This vulnerability in Nextcloud Calendar allows attackers to blindly book appointments using sequential IDs without needing the appointment token. It ...

Dec 5, 2025

About CWE-639 (CWE-639)

Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.

External reference: View CWE-639 on MITRE CWE →

Monitor CWE-639 Vulnerabilities

Get alerted when new CWE-639 CVEs affect your infrastructure.

Start Monitoring Free