Threats Tagged 'cwe-290'
View all threats tagged with 'cwe-290'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-290'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-64665: CWE-287: Improper Authentication in statamic cmsCVE-2026-64665 0 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by email address alone. Exploitation requires OAuth to be explicitly enabled with such a provider. This issue is fixed in versions 5.74.1 and 6.24.0. Join the discussion | CVE Database V5 | 08/06/2026, 19:25:01 UTC Added: 08/06/2026, 22:13:27 UTC |
CVE-2026-65570: CWE-290 Authentication Bypass by Spoofing in Hamid Alinia Login with phone numberCVE-2026-65570 0 Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions. Join the discussion | CVE Database V5 | 08/06/2026, 14:27:40 UTC Added: 08/06/2026, 14:42:03 UTC |
CVE-2026-65502: CWE-290 Authentication Bypass by Spoofing in bdthemes Element Pack Elementor AddonsCVE-2026-65502 0 Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. Join the discussion | CVE Database V5 | 08/06/2026, 14:27:22 UTC Added: 08/06/2026, 14:41:59 UTC |
CVE-2026-32469: CWE-290 Authentication Bypass by Spoofing in WPKube CAPTCHA 4WPCVE-2026-32469 0 Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. Join the discussion | CVE Database V5 | 08/06/2026, 14:27:17 UTC Added: 08/06/2026, 14:41:57 UTC |
CVE-2026-48063: CWE-290: Authentication Bypass by Spoofing in WhiskeySockets BaileysCVE-2026-48063 0 Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, injecting fake previous context or "on-demand" sync. This issue has been fixed in versions 6.7.22 and 7.0.0-rc12. Join the discussion | CVE Database V5 | 08/03/2026, 20:55:08 UTC Added: 08/03/2026, 21:18:56 UTC |
CVE-2026-14840: CWE-290 Authentication Bypass by Spoofing in YOP PollCVE-2026-14840 0 A vulnerability in the YOP Poll WordPress plugin before version 7.0.6 allows unauthenticated attackers to bypass per-IP vote restrictions by exploiting improper validation of client-controlled forwarding headers. This enables unlimited voting on public polls. Join the discussion | CVE Database V5 | 08/01/2026, 06:00:14 UTC Added: 08/01/2026, 06:48:51 UTC |
CVE-2026-13143: CWE-290 Authentication Bypass by Spoofing in WP TravelCVE-2026-13143 0 CVE-2026-13143 is a medium severity vulnerability in the WP Travel WordPress plugin before version 11.8.1. The plugin fails to verify PayPal Instant Payment Notifications (IPNs) through the required PayPal post-back handshake. This flaw allows unauthenticated attackers to spoof payment notifications, causing arbitrary pending bookings to be marked as paid with attacker-chosen amounts. Join the discussion | CVE Database V5 | 07/30/2026, 06:00:11 UTC Added: 07/30/2026, 06:24:06 UTC |
CVE-2026-11870: CWE-290 Authentication Bypass by Spoofing in WP Ghost (Hide My WP Ghost)CVE-2026-11870 0 CVE-2026-11870 is a medium severity vulnerability in the WP Ghost (Hide My WP Ghost) WordPress plugin before version 7.0.05. The plugin fails to verify that client IP information originates from a trusted proxy before trusting HTTP headers that can be controlled by an attacker. This allows unauthenticated attackers to spoof their IP address, bypassing the plugin's brute-force protection and downgrading its firewall by matching a hardcoded whitelisted IP range. Join the discussion | CVE Database V5 | 07/30/2026, 06:00:10 UTC Added: 07/30/2026, 06:24:06 UTC |
CVE-2026-11922: CWE-290 Authentication Bypass by Spoofing in zenml-io zenml-io/zenmlCVE-2026-11922 0 A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks. Join the discussion | CVE Database V5 | 07/24/2026, 03:27:39 UTC Added: 07/24/2026, 03:37:42 UTC |
CVE-2026-64875: CWE-290 Authentication Bypass by Spoofing in regularlabs.com GeoIP extension for JoomlaCVE-2026-64875 0 Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass. Join the discussion | CVE Database V5 | 07/23/2026, 09:13:55 UTC Added: 07/23/2026, 09:22:46 UTC |
Showing 1 to 10 of 20 results