CWE-472

CWE-472 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-472, highest CVSS first.

  1. MEDIUM 5.3CVE-2026-86838

    The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing t…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.3CVE-2026-85010

    The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-cho…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-94374public PoC

    MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the a…

    AI risk analysis on Exploit-DB.ai →