CWE-639: CWE-639
Yearly Trend
Top Affected Vendors
All CWE-639 CVEs (519)
This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Saleor e-commerce platform that allows unauthenticated attackers to acc...
Jan 24, 2026This vulnerability allows attackers to bypass authorization controls in Solvera Software Services Trade Inc.'s Teknoera software by manipulating user-...
Jan 22, 2026This vulnerability allows attackers to bypass authorization controls by manipulating user-controlled keys in EXERT Computer Technologies' Education Ma...
Jan 22, 2026This vulnerability in OPEXUS eComplaint allows unauthenticated attackers to download sensitive files by guessing predictable charge numbers. It affect...
Jan 8, 2026This vulnerability allows attackers to bypass authorization controls in Utarit Informatics Services Inc. SoliClub by manipulating user-controlled keys...
Dec 18, 2025CVE-2023-53930 is an insecure direct object reference vulnerability in ProjectSend r1605 that allows unauthenticated attackers to download private fil...
Dec 17, 2025This vulnerability allows unauthenticated attackers to read arbitrary form definitions and submission records in Ninja Forms WordPress plugin. Attacke...
Dec 17, 2025This vulnerability allows attackers to bypass authorization mechanisms in Menulux Software Inc.'s Mobile App by manipulating user-controlled keys to e...
Dec 16, 2025WebITR software developed by Uniong contains an authentication bypass vulnerability that allows authenticated remote attackers to log into the system ...
Nov 28, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in classroomio version 0.1.13 that allows unauthorized users to access and...
Nov 26, 2025This vulnerability allows unauthenticated attackers to bypass authorization and retrieve payment method nonces for any stored payment token in the Woo...
Nov 12, 2025DWSurvey 6.14.0 has an access control vulnerability that allows authenticated users to delete other users' questionnaires by manipulating questionnair...
Nov 5, 2025The Event Tickets and Registration WordPress plugin has a payment bypass vulnerability that allows unauthenticated attackers to obtain paid tickets wi...
Oct 18, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Sergestec's Exito v8.0 that allows attackers to access other customers'...
Oct 16, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner's general enquiry web service that allows unauthorized...
Sep 30, 2025An Insecure Direct Object Reference (IDOR) vulnerability in the PdfHandler component of Agenzia Impresa Eccobook allows unauthenticated attackers to a...
Aug 5, 2025An Insecure Direct Object Reference (IDOR) vulnerability in Dippy chat.dippy.ai v2 allows attackers to access other users' conversation histories by m...
Jul 21, 2025This authentication bypass vulnerability allows a low-privileged remote attacker who possesses another user's second factor (like a hardware token or ...
Jun 24, 2025An Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS allows attackers to bypass authentication and access private admin area...
Jun 10, 2025An Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS allows attackers to bypass authentication and access private admin area...
Jun 10, 2025This vulnerability allows attackers to change registered email addresses of other users, enabling account takeover. It affects systems with insufficie...
Apr 15, 2025The NP Quote Request for WooCommerce WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to r...
Mar 20, 2025CVE-2024-8261 is an authorization bypass vulnerability in Proliz Software OBS that allows attackers to access unauthorized functionality by manipulati...
Mar 3, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Newgensoft OmniDocs that allows attackers to access other users' config...
Feb 6, 2025An IDOR vulnerability in AbsysNet 2.3.1 allows remote attackers to hijack unauthenticated user sessions by brute-forcing session identifiers on the /c...
Nov 18, 2024This vulnerability allows authenticated users with bulk messaging permissions to send messages to users who should not be visible in activity non-resp...
Nov 7, 2024This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Paid Memberships Pro WordPress plugin. Attackers can manipulate use...
Nov 1, 2024An Insecure Direct Object Reference (IDOR) vulnerability in Phpgurukul's Beauty Parlour Management System v1.1 allows attackers to access other custom...
Oct 31, 2024This vulnerability allows unauthenticated attackers to access all user-submitted form data stored by the powermail extension in TYPO3. It affects TYPO...
Sep 17, 2024This vulnerability allows attackers to bypass authorization controls in Utarit Information SoliClub mobile apps by manipulating user-controlled keys, ...
Sep 12, 2024This vulnerability allows attackers to bypass authorization by manipulating user-controlled keys, enabling unauthorized access to other users' data or...
Aug 18, 2024This vulnerability allows attackers to bypass IP allow-lists in Traefik reverse proxy by sending HTTP/3 early data requests with spoofed IP addresses ...
Jul 5, 2024CVE-2024-33818 is an Insecure Direct Object Reference (IDOR) vulnerability in Globitel KSA SpeechLog v8.1 that allows attackers to access unauthorized...
May 14, 2024An Insecure Direct Object Reference (IDOR) vulnerability in Janto Ticketing Software version 4.3r10 allows remote attackers to access other users' eve...
May 7, 2024This SQL injection vulnerability in Vaales Technologies V_QRS allows remote attackers to extract sensitive information from the database by manipulati...
May 1, 2024This vulnerability allows remote attackers to read arbitrary files on novel-plus servers by manipulating the filePath parameter in GET requests. It af...
Apr 30, 2024This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in GNU Savane that allows remote attackers to delete arbitrary files on th...
Apr 8, 2024This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Kali Forms WordPress plugin. Attackers can bypass authorization by ...
Jan 31, 2024This IDOR vulnerability in ModernaNet Hospital Management System allows attackers to access sensitive medical records by manipulating URL parameters. ...
Jan 29, 2024This vulnerability allows unauthenticated attackers to bypass authorization by manipulating user-controlled keys in the WooCommerce Stripe Payment Gat...
Jan 5, 2024Archer Platform 6.x contains an insecure direct object reference vulnerability that allows authenticated malicious users in multi-instance installatio...
Dec 12, 2023OpenZFS vulnerability where file contents can be replaced with zero-valued bytes during certain copy operations, potentially disabling security mechan...
Nov 24, 2023An unauthenticated attacker can access any student's files by manipulating the URL path in openSIS Classic Community Edition. This affects all install...
Nov 20, 2023CVE-2023-37543 is an Insecure Direct Object Reference (IDOR) vulnerability in Cacti that allows attackers to access any monitoring graph by manipulati...
Aug 10, 2023This vulnerability allows attackers to access sensitive information about GitLab groups through an insecure direct object reference in the merge reque...
Apr 15, 2023This vulnerability in the WP-EMail WordPress plugin allows attackers to bypass IP-based anti-spam restrictions by spoofing their IP address using HTTP...
Jun 20, 2022This vulnerability allows remote attackers to browse local files on Atlassian Fisheye and Crucible servers via an Insecure Direct Object Reference (ID...
Mar 16, 2022This vulnerability allows unauthenticated remote attackers to sequentially access survey user data by manipulating the ID parameter in the UploadedIma...
Jan 28, 2022CVE-2022-22828 is an insecure direct object reference vulnerability in Synametrics SynaMan file transfer software. It allows remote attackers to acces...
Jan 27, 2022CVE-2021-22967 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS that allows unauthenticated users to access restricted file...
Nov 19, 2021About CWE-639 (CWE-639)
Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.
External reference: View CWE-639 on MITRE CWE →
Monitor CWE-639 Vulnerabilities
Get alerted when new CWE-639 CVEs affect your infrastructure.
Start Monitoring Free