CWE-639
CVEs classified under CWE-639, newest first.
670 CVEsRSS
CVE-2026-11900Medium· 4.3The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode. This is due to the replace_a…
CVE-2026-9180Medium· 5.3The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4
The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpo…
GHSA-j5mc-p8qg-39j7LowKimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
CVE-2026-50194High· 8.2Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
Steeltoe vulnerable to management-port isolation bypass via spoofed Host header
CVE-2026-50283MediumCraft CMS: Unauthorized Deletion of Source Assets During File Replacement
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
GHSA-f9ff-5x35-7gfwHighGrackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
GHSA-6vg3-hgrw-p5gfMedium· 5.4SurrealDB has an Authorization Bypass via Composite Record-id Paths
SurrealDB has an Authorization Bypass via Composite Record-id Paths
CVE-2026-47198High· 8.5Paymenter has URL parameter injection that bypasses paid plan limits at checkout
Paymenter has URL parameter injection that bypasses paid plan limits at checkout
CVE-2026-13534Medium· 5.0A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7
A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument s…
CVE-2026-13512Medium· 6.3A vulnerability was identified in Databend up to 1.2.881 on HTTP
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handl…
CVE-2026-12411High· 8.4Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when securi…
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when securi…
CVE-2026-52782Critical· 9.9PoCOpenProject is open-source, web-based project management software
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" l…
CVE-2026-49355Medium· 4.3OpenProject is open-source, web-based project management software
OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked work package that belongs to a private/…
CVE-2026-44732Medium· 4.3OpenProject is open-source, web-based project management software
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and the…
CVE-2026-44731Medium· 4.3OpenProject is open-source, web-based project management software
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name,…
CVE-2026-49258High· 8.8Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
GHSA-7vfx-4246-jcfhHighSolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings
SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings
GHSA-q6xx-5vr8-p898Critical· 9.9Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
CVE-2026-49339High· 7.1gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
CVE-2026-49338High· 7.1Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
GHSA-vjr9-f93j-mjr7High· 8.1Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-52812HighGogs: LFS dedupe path leaks private repo content across tenants
Gogs: LFS dedupe path leaks private repo content across tenants
CVE-2026-54518Medium· 6.5jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass (CVE-2026-54518)
A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security view restrictions by sending specially crafted JSON (JavaScript Object Notation) data. The UnwrappedPropertyHandler component, which proce…
CVE-2026-6062Medium· 6.4Mattermost doesn't validate channel ownership of an existing subscription before applying edits
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
CVE-2026-52799High· 7.5Gogs Missing Authorization in Attachment Download
Gogs Missing Authorization in Attachment Download
CVE-2026-56120Critical· 9.6OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
CVE-2026-53726Mediumparse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL
parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL
CVE-2026-55255Critical· 9.9CISA KEVPoCLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
GHSA-x26h-xmv8-gxf7Highstigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
GHSA-xhv3-q4xx-349rHighstistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)