Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-290'

View all threats tagged with 'cwe-290'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-290

Threats Tagged 'cwe-290'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-64665: CWE-287: Improper Authentication in statamic cmsCVE-2026-64665
0

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such a provider. This issue is fixed in versions 5.74.1 and 6.24.0.

Join the discussion
CVE-2026-65570: CWE-290 Authentication Bypass by Spoofing in Hamid Alinia Login with phone numberCVE-2026-65570
0

Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.

Join the discussion
CVE-2026-65502: CWE-290 Authentication Bypass by Spoofing in bdthemes Element Pack Elementor AddonsCVE-2026-65502
0

Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

Join the discussion
CVE-2026-32469: CWE-290 Authentication Bypass by Spoofing in WPKube CAPTCHA 4WPCVE-2026-32469
0

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

Join the discussion
CVE-2026-48063: CWE-290: Authentication Bypass by Spoofing in WhiskeySockets BaileysCVE-2026-48063
0

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, injecting fake previous context or "on-demand" sync. This issue has been fixed in versions 6.7.22 and 7.0.0-rc12.

Join the discussion
CVE-2026-14840: CWE-290 Authentication Bypass by Spoofing in YOP PollCVE-2026-14840
0

A vulnerability in the YOP Poll WordPress plugin before version 7.0.6 allows unauthenticated attackers to bypass per-IP vote restrictions by exploiting improper validation of client-controlled forwarding headers. This enables unlimited voting on public polls.

Join the discussion
CVE-2026-13143: CWE-290 Authentication Bypass by Spoofing in WP TravelCVE-2026-13143
0

CVE-2026-13143 is a medium severity vulnerability in the WP Travel WordPress plugin before version 11.8.1. The plugin fails to verify PayPal Instant Payment Notifications (IPNs) through the required PayPal post-back handshake. This flaw allows unauthenticated attackers to spoof payment notifications, causing arbitrary pending bookings to be marked as paid with attacker-chosen amounts.

Join the discussion
CVE-2026-11870: CWE-290 Authentication Bypass by Spoofing in WP Ghost (Hide My WP Ghost)CVE-2026-11870
0

CVE-2026-11870 is a medium severity vulnerability in the WP Ghost (Hide My WP Ghost) WordPress plugin before version 7.0.05. The plugin fails to verify that client IP information originates from a trusted proxy before trusting HTTP headers that can be controlled by an attacker. This allows unauthenticated attackers to spoof their IP address, bypassing the plugin's brute-force protection and downgrading its firewall by matching a hardcoded whitelisted IP range.

Join the discussion
CVE-2026-11922: CWE-290 Authentication Bypass by Spoofing in zenml-io zenml-io/zenmlCVE-2026-11922
0

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks.

Join the discussion
CVE-2026-64875: CWE-290 Authentication Bypass by Spoofing in regularlabs.com GeoIP extension for JoomlaCVE-2026-64875
0

Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.

Join the discussion

Showing 1 to 10 of 20 results

Filters:Tag: cwe-290
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses