CWE-472
CWE-472 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-472, highest CVSS first.
- MEDIUM 5.3CVE-2026-86838
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing t…
- MEDIUM 5.3CVE-2026-85010
The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place orders for an attacker-cho…
- UNSCOREDCVE-2026-94374public PoC
MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves each one. Unlike the a…