CWE-639

CWE-639 · 12 records · 7 with a public proof-of-concept

Records the NVD classes under CWE-639, highest CVSS first.

  1. HIGH 8.3CVE-2026-71242public PoC

    Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). Any authenticated user of

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.3CVE-2026-55739public PoC

    Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-71251public PoC

    Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the requesting porta

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-11454

    The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.2 via the GET /wp-json/gh/v4/contacts/<id> REST endpoint. The endpoint's permission cal

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.3CVE-2026-18818

    A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation can lead to authorization bypass. The att

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.3CVE-2026-16981

    The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one of its shipping-label download endpoints, so an unauthenticated attacker can enumerate sequ

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 4.3CVE-2026-70488public PoC

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids supplied in the request b

    AI risk analysis on Exploit-DB.ai →

  8. LOW 2.7CVE-2026-16746

    The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in one of its REST API endpoints, allowing any vendor-level user to read other vendors' commission and financial data.

    AI risk analysis on Exploit-DB.ai →

  9. LOW 2.7CVE-2026-16070

    The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-70476public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organi

    AI risk analysis on Exploit-DB.ai →

  11. UNSCOREDCVE-2026-69258public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowD

    AI risk analysis on Exploit-DB.ai →

  12. UNSCOREDCVE-2026-69250public PoC

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request

    AI risk analysis on Exploit-DB.ai →