CWE-639: CWE-639

519
Total CVEs
63
Critical
165
High
6.6
Avg CVSS

Yearly Trend

2026
89
2025
239
2024
130
2023
28
2022
16

Top Affected Vendors

1 Growatt 12
2 Nextcloud 10
3 Easyappointments 8
4 Liferay 8
5 Boldworkplanner 8
6 Lunary 6
7 Gitlab 6
8 Open Emr 5
9 Wpjobportal 5
10 Apache 4

All CWE-639 CVEs (519)

CVE-2025-64282
4.3

This vulnerability allows attackers to bypass authorization controls in RadiusTheme Radius Blocks WordPress plugin by manipulating user-controlled key...

Dec 18, 2025
CVE-2025-13110
4.3

This vulnerability in the HUSKY – Products Filter Professional for WooCommerce WordPress plugin allows authenticated attackers with subscriber-level...

Dec 18, 2025
CVE-2025-64012
4.3

InvoicePlane versions before commit debb446c are vulnerable to an authorization bypass that allows users to view invoices belonging to other accounts....

Dec 16, 2025
CVE-2025-64011
4.3

Nextcloud Server 30.0.0 contains an Insecure Direct Object Reference (IDOR) vulnerability in the /core/preview endpoint. Authenticated users can acces...

Dec 12, 2025
CVE-2025-14356
4.3

The Ultra Addons for Contact Form 7 WordPress plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level a...

Dec 12, 2025
CVE-2025-61950
4.3

This vulnerability allows authenticated users in GroupSession to modify memo fields in Circular notices that should be non-editable due to improper au...

Dec 12, 2025
CVE-2025-11247
4.3

This vulnerability allows authenticated GitLab users to access sensitive information from private projects by crafting specific GraphQL queries. It af...

Dec 11, 2025
CVE-2025-13125
4.3

This vulnerability allows attackers to bypass authorization mechanisms by manipulating user-controlled keys in DijiDemi software, potentially accessin...

Dec 10, 2025
CVE-2025-67594
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the ThimPress Thim Elementor Kit WordPress plugin. Attackers can bypass...

Dec 9, 2025
CVE-2025-66553
4.3

CVE-2025-66553 is an authorization bypass vulnerability in Nextcloud Tables where authenticated users can view metadata of columns in other tables by ...

Dec 5, 2025
CVE-2025-66513
4.3

Nextcloud Tables had an authorization bypass vulnerability where unprivileged users could view which tables were shared with which groups/users and th...

Dec 5, 2025
CVE-2025-66547
4.3

This vulnerability allows non-privileged Nextcloud users to modify tags on files they shouldn't have access to through bulk tagging operations. It aff...

Dec 5, 2025
CVE-2025-13109
4.3

This vulnerability in the HUSKY – Products Filter Professional for WooCommerce WordPress plugin allows authenticated attackers with subscriber-level...

Dec 3, 2025
CVE-2025-66306
4.3

Grav CMS versions before 1.8.0-beta.27 contain an IDOR vulnerability in the admin panel that allows low-privilege users to access sensitive informatio...

Dec 1, 2025
CVE-2025-65670
4.3

This IDOR vulnerability in classroomio 0.1.13 allows students to temporarily access admin/teacher endpoints by manipulating course IDs in URLs, leadin...

Nov 26, 2025
CVE-2025-13452
4.3

This vulnerability allows unauthenticated attackers to impersonate any WordPress user and inject arbitrary messages into WooCommerce order conversatio...

Nov 25, 2025
CVE-2025-13382
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to rename files uploaded by other users via the Fronten...

Nov 25, 2025
CVE-2025-10039
4.3

The ELEX WordPress HelpDesk plugin has an Insecure Direct Object Reference vulnerability that allows authenticated users with Subscriber-level access ...

Nov 21, 2025
CVE-2025-12086
4.3

This vulnerability in the Return Refund and Exchange For WooCommerce WordPress plugin allows authenticated attackers with Subscriber-level access or h...

Nov 21, 2025
CVE-2025-12366
4.3

This vulnerability allows authenticated WordPress users with Author-level permissions or higher to replace media files belonging to other users, inclu...

Nov 13, 2025
CVE-2025-12833
4.3

This vulnerability allows authenticated WordPress users with author-level permissions or higher to attach arbitrary image files to any location within...

Nov 12, 2025
CVE-2025-12087
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete wishlist items from other users' wishlists. I...

Nov 12, 2025
CVE-2025-11748
4.3

The Groups plugin for WordPress has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Subscriber-level access...

Nov 8, 2025
CVE-2025-6833
4.3

This vulnerability allows authenticated WordPress users with subscriber-level access or higher to manipulate other users' time clock entries by exploi...

Oct 22, 2025
CVE-2025-10570
4.3

The Flexible Refund and Return Order for WooCommerce WordPress plugin has an authorization flaw that allows authenticated users (even with basic subsc...

Oct 22, 2025
CVE-2025-60511
4.3

The Moodle OpenAI Chat Block plugin has an Insecure Direct Object Reference vulnerability that allows authenticated students to impersonate other user...

Oct 21, 2025
CVE-2025-11176
4.3

The Quick Featured Images WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Author-level...

Oct 15, 2025
CVE-2025-62252
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users in one virtual i...

Oct 13, 2025
CVE-2025-62241
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay DXP that allows authenticated users from one virtual instance t...

Oct 13, 2025
CVE-2025-62242
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users to access other ...

Oct 13, 2025
CVE-2025-59687
4.3

IMPAQTR Aurora versions before 1.36 contain an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to access other u...

Oct 1, 2025
CVE-2025-43827
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP that allows authenticated users from one virtual...

Sep 30, 2025
CVE-2025-41094
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner software that allows authenticated users to access con...

Sep 30, 2025
CVE-2025-41095
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner software. Authenticated users can access planning coun...

Sep 30, 2025
CVE-2025-41096
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner software that allows authenticated users to access con...

Sep 30, 2025
CVE-2025-41097
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner software that allows authenticated users to access bas...

Sep 30, 2025
CVE-2025-41091
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner that allows authenticated users to access calendar det...

Sep 30, 2025
CVE-2025-41092
4.3

This IDOR vulnerability in BOLD Workplanner allows authenticated users to access time records details using unauthorized internal identifiers due to i...

Sep 30, 2025
CVE-2025-41093
4.3

An Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner allows authenticated users to access basic contract details using unautho...

Sep 30, 2025
CVE-2025-43810
4.3

An Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP allows authenticated users from one virtual instance to add notes t...

Sep 22, 2025
CVE-2025-43803
4.3

An insecure direct object reference (IDOR) vulnerability in Liferay's Contacts Center widget allows remote attackers to access contact information the...

Sep 19, 2025
CVE-2025-10719
4.3

CVE-2025-10719 is an Insecure Direct Object Reference vulnerability in Tronclass by WisdomGarden that allows authenticated users to access other users...

Sep 19, 2025
CVE-2025-43782
4.3

An Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal and DXP allows authenticated users to access workflow definitions by name v...

Sep 11, 2025
CVE-2025-58597
4.3

This vulnerability allows attackers to bypass authorization controls in wpForo Forum by manipulating user-controlled keys, potentially accessing unaut...

Sep 3, 2025
CVE-2025-56254
4.3

PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference (IDOR) vulnerability where authenticated users can manipu...

Sep 2, 2025
CVE-2025-50340
4.3

An authenticated SOGo Webmail user can send emails impersonating other users by manipulating sender identifiers in email requests. This IDOR vulnerabi...

Aug 4, 2025
CVE-2025-49978
4.3

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the eyecix JobSearch WordPress plugin that allows attackers to bypass a...

Jun 20, 2025
CVE-2025-1327
4.3

The Homey WordPress theme has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Subscriber-level access or hi...

May 2, 2025
CVE-2025-3636
4.3

This vulnerability in Moodle allows unauthorized users to access RSS feeds due to insufficient permission checks. Any Moodle instance with RSS feeds e...

Apr 25, 2025
CVE-2025-1284
4.3

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to view other users' invoices and orders containing sen...

Apr 24, 2025

About CWE-639 (CWE-639)

Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.

External reference: View CWE-639 on MITRE CWE →

Monitor CWE-639 Vulnerabilities

Get alerted when new CWE-639 CVEs affect your infrastructure.

Start Monitoring Free