CWE-639: CWE-639

519
Total CVEs
63
Critical
165
High
6.6
Avg CVSS

Yearly Trend

2026
89
2025
239
2024
130
2023
28
2022
16

Top Affected Vendors

1 Growatt 12
2 Nextcloud 10
3 Easyappointments 8
4 Liferay 8
5 Boldworkplanner 8
6 Lunary 6
7 Gitlab 6
8 Open Emr 5
9 Wpjobportal 5
10 Apache 4

All CWE-639 CVEs (519)

CVE-2026-24136
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Saleor e-commerce platform that allows unauthenticated attackers to acc...

Jan 24, 2026
CVE-2025-10855
7.5

This vulnerability allows attackers to bypass authorization controls in Solvera Software Services Trade Inc.'s Teknoera software by manipulating user-...

Jan 22, 2026
CVE-2025-10024
7.5

This vulnerability allows attackers to bypass authorization controls by manipulating user-controlled keys in EXERT Computer Technologies' Education Ma...

Jan 22, 2026
CVE-2026-22235
7.5

This vulnerability in OPEXUS eComplaint allows unauthenticated attackers to download sensitive files by guessing predictable charge numbers. It affect...

Jan 8, 2026
CVE-2025-1031
7.5

This vulnerability allows attackers to bypass authorization controls in Utarit Informatics Services Inc. SoliClub by manipulating user-controlled keys...

Dec 18, 2025
CVE-2023-53930
7.5

CVE-2023-53930 is an insecure direct object reference vulnerability in ProjectSend r1605 that allows unauthenticated attackers to download private fil...

Dec 17, 2025
CVE-2025-11924
7.5

This vulnerability allows unauthenticated attackers to read arbitrary form definitions and submission records in Ninja Forms WordPress plugin. Attacke...

Dec 17, 2025
CVE-2025-13474
7.5

This vulnerability allows attackers to bypass authorization mechanisms in Menulux Software Inc.'s Mobile App by manipulating user-controlled keys to e...

Dec 16, 2025
CVE-2025-13768
7.5

WebITR software developed by Uniong contains an authentication bypass vulnerability that allows authenticated remote attackers to log into the system ...

Nov 28, 2025
CVE-2025-65672
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in classroomio version 0.1.13 that allows unauthorized users to access and...

Nov 26, 2025
CVE-2025-12903
7.5

This vulnerability allows unauthenticated attackers to bypass authorization and retrieve payment method nonces for any stored payment token in the Woo...

Nov 12, 2025
CVE-2025-63248
7.5

DWSurvey 6.14.0 has an access control vulnerability that allows authenticated users to delete other users' questionnaires by manipulating questionnair...

Nov 5, 2025
CVE-2025-11517
7.5

The Event Tickets and Registration WordPress plugin has a payment bypass vulnerability that allows unauthenticated attackers to obtain paid tickets wi...

Oct 18, 2025
CVE-2025-41020
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Sergestec's Exito v8.0 that allows attackers to access other customers'...

Oct 16, 2025
CVE-2025-41098
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner's general enquiry web service that allows unauthorized...

Sep 30, 2025
CVE-2025-51628
7.5

An Insecure Direct Object Reference (IDOR) vulnerability in the PdfHandler component of Agenzia Impresa Eccobook allows unauthenticated attackers to a...

Aug 5, 2025
CVE-2025-51868
7.5

An Insecure Direct Object Reference (IDOR) vulnerability in Dippy chat.dippy.ai v2 allows attackers to access other users' conversation histories by m...

Jul 21, 2025
CVE-2025-3091
7.5

This authentication bypass vulnerability allows a low-privileged remote attacker who possesses another user's second factor (like a hardware token or ...

Jun 24, 2025
CVE-2025-40658
7.5

An Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS allows attackers to bypass authentication and access private admin area...

Jun 10, 2025
CVE-2025-40660
7.5

An Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS allows attackers to bypass authentication and access private admin area...

Jun 10, 2025
CVE-2025-27939
7.5

This vulnerability allows attackers to change registered email addresses of other users, enabling account takeover. It affects systems with insufficie...

Apr 15, 2025
CVE-2024-13558
7.5

The NP Quote Request for WooCommerce WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to r...

Mar 20, 2025
CVE-2024-8261
7.5

CVE-2024-8261 is an authorization bypass vulnerability in Proliz Software OBS that allows attackers to access unauthorized functionality by manipulati...

Mar 3, 2025
CVE-2024-39033
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Newgensoft OmniDocs that allows attackers to access other users' config...

Feb 6, 2025
CVE-2024-11318
7.5

An IDOR vulnerability in AbsysNet 2.3.1 allows remote attackers to hijack unauthenticated user sessions by brute-forcing session identifiers on the /c...

Nov 18, 2024
CVE-2024-43438
7.5

This vulnerability allows authenticated users with bulk messaging permissions to send messages to users who should not be visible in activity non-resp...

Nov 7, 2024
CVE-2024-37277
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Paid Memberships Pro WordPress plugin. Attackers can manipulate use...

Nov 1, 2024
CVE-2024-51066
7.5

An Insecure Direct Object Reference (IDOR) vulnerability in Phpgurukul's Beauty Parlour Management System v1.1 allows attackers to access other custom...

Oct 31, 2024
CVE-2024-47047
7.5

This vulnerability allows unauthenticated attackers to access all user-submitted form data stored by the powermail extension in TYPO3. It affects TYPO...

Sep 17, 2024
CVE-2024-3305
7.5

This vulnerability allows attackers to bypass authorization controls in Utarit Information SoliClub mobile apps by manipulating user-controlled keys, ...

Sep 12, 2024
CVE-2024-43315
7.5

This vulnerability allows attackers to bypass authorization by manipulating user-controlled keys, enabling unauthorized access to other users' data or...

Aug 18, 2024
CVE-2024-39321
7.5

This vulnerability allows attackers to bypass IP allow-lists in Traefik reverse proxy by sending HTTP/3 early data requests with spoofed IP addresses ...

Jul 5, 2024
CVE-2024-33818
7.5

CVE-2024-33818 is an Insecure Direct Object Reference (IDOR) vulnerability in Globitel KSA SpeechLog v8.1 that allows attackers to access unauthorized...

May 14, 2024
CVE-2024-4538
7.5

An Insecure Direct Object Reference (IDOR) vulnerability in Janto Ticketing Software version 4.3r10 allows remote attackers to access other users' eve...

May 7, 2024
CVE-2024-24312
7.5

This SQL injection vulnerability in Vaales Technologies V_QRS allows remote attackers to extract sensitive information from the database by manipulati...

May 1, 2024
CVE-2024-33383
7.5

This vulnerability allows remote attackers to read arbitrary files on novel-plus servers by manipulating the filePath parameter in GET requests. It af...

Apr 30, 2024
CVE-2024-27630
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in GNU Savane that allows remote attackers to delete arbitrary files on th...

Apr 8, 2024
CVE-2024-22305
7.5

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Kali Forms WordPress plugin. Attackers can bypass authorization by ...

Jan 31, 2024
CVE-2024-23747
7.5

This IDOR vulnerability in ModernaNet Hospital Management System allows attackers to access sensitive medical records by manipulating URL parameters. ...

Jan 29, 2024
CVE-2023-51502
7.5

This vulnerability allows unauthenticated attackers to bypass authorization by manipulating user-controlled keys in the WooCommerce Stripe Payment Gat...

Jan 5, 2024
CVE-2023-48641
7.5

Archer Platform 6.x contains an insecure direct object reference vulnerability that allows authenticated malicious users in multi-instance installatio...

Dec 12, 2023
CVE-2023-49298
7.5

OpenZFS vulnerability where file contents can be replaced with zero-valued bytes during certain copy operations, potentially disabling security mechan...

Nov 24, 2023
CVE-2023-38884
7.5

An unauthenticated attacker can access any student's files by manipulating the URL path in openSIS Classic Community Edition. This affects all install...

Nov 20, 2023
CVE-2023-37543
7.5

CVE-2023-37543 is an Insecure Direct Object Reference (IDOR) vulnerability in Cacti that allows attackers to access any monitoring graph by manipulati...

Aug 10, 2023
CVE-2018-17455
7.5

This vulnerability allows attackers to access sensitive information about GitLab groups through an insecure direct object reference in the merge reque...

Apr 15, 2023
CVE-2022-1614
7.5

This vulnerability in the WP-EMail WordPress plugin allows attackers to bypass IP-based anti-spam restrictions by spoofing their IP address using HTTP...

Jun 20, 2022
CVE-2021-43957
7.5

This vulnerability allows remote attackers to browse local files on Atlassian Fisheye and Crucible servers via an Insecure Direct Object Reference (ID...

Mar 16, 2022
CVE-2021-41608
7.5

This vulnerability allows unauthenticated remote attackers to sequentially access survey user data by manipulating the ID parameter in the UploadedIma...

Jan 28, 2022
CVE-2022-22828
7.5

CVE-2022-22828 is an insecure direct object reference vulnerability in Synametrics SynaMan file transfer software. It allows remote attackers to acces...

Jan 27, 2022
CVE-2021-22967
7.5

CVE-2021-22967 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS that allows unauthenticated users to access restricted file...

Nov 19, 2021

About CWE-639 (CWE-639)

Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.

External reference: View CWE-639 on MITRE CWE →

Monitor CWE-639 Vulnerabilities

Get alerted when new CWE-639 CVEs affect your infrastructure.

Start Monitoring Free