Threats Tagged 'cwe-345'
View all threats tagged with 'cwe-345'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-345'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-58262: CWE-345: Insufficient Verification of Data Authenticity in klever-io klever-goCVE-2026-58262 0 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These padding bits do not correspond to any validator and are ignored by the actual BLS aggregate-signature check, so a malicious or compromised block producer can set them to reach the required quorum while gathering fewer genuine validator signatures than the protocol demands. As a result, nodes that import or intercept the header accept it as correctly signed without a real two-thirds quorum, weakening consensus safety and undermining finality. This issue is fixed in version 1.7.20. Join the discussion | CVE Database V5 | 08/07/2026, 22:00:57 UTC Added: 08/07/2026, 22:12:01 UTC |
CVE-2026-47664: CWE-20: Improper Input Validation in aehrc pathlingCVE-2026-47664 0 Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `exportUrl` and uses it as the remote FHIR Bulk Export endpoint without constraining it to a trusted source. When PNP credentials are configured, Pathling builds a credentialed bulk-export client targeting the caller-chosen host, downloads manifest-selected files, and then reclassifies those staged files as trusted local `file://` imports - bypassing the configured `allowableSources` allowlist that protects the ordinary `$import` operation. This is fixed in Pathling Server 2.0.0. As a workaround, disable the `$import-pnp` operation (`pathling.operations.importPnpEnabled=false`) or do not configure PNP credentials. Join the discussion | CVE Database V5 | 08/07/2026, 20:28:06 UTC Added: 08/07/2026, 20:56:45 UTC |
CVE-2026-15239: CWE-345 Insufficient Verification of Data Authenticity in Simple CAPTCHA with Cloudflare TurnstileCVE-2026-15239 0 The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and then replay token-less form submissions for a short window, defeating the anti-abuse protection the plugin provides. Join the discussion | CVE Database V5 | 08/07/2026, 07:25:36 UTC Added: 08/07/2026, 07:41:50 UTC |
CVE-2026-15211: CWE-345 Insufficient Verification of Data Authenticity in Subscriptions for WooCommerceCVE-2026-15211 0 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without comparing the captured amount to the order total. This allows an attacker (unauthenticated where guest checkout is enabled) to substitute an approved, uncaptured PayPal order token and have an expensive order marked paid without paying its price. Join the discussion | CVE Database V5 | 08/07/2026, 07:25:35 UTC Added: 08/07/2026, 07:41:50 UTC |
CVE-2026-15148: CWE-345 Insufficient Verification of Data Authenticity in WP Events ManagerCVE-2026-15148 0 The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the merchant, including other users' bookings. Join the discussion | CVE Database V5 | 08/07/2026, 07:25:34 UTC Added: 08/07/2026, 07:41:50 UTC |
CVE-2026-19127: CWE-345 in GitroomHQ postiz-appCVE-2026-19127 0 An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction. Join the discussion | CVE Database V5 | 08/06/2026, 17:02:44 UTC Added: 08/06/2026, 22:13:12 UTC |
CVE-2026-15208: CWE-345 Insufficient Verification of Data Authenticity in RegistrationMagicCVE-2026-15208 0 The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid registration with any genuinely-completed low-value capture, and replay a single capture across unlimited registrations because captures are not de-duplicated. Join the discussion | CVE Database V5 | 08/06/2026, 17:07:32 UTC Added: 08/06/2026, 22:13:09 UTC |
CVE-2026-15152: CWE-345 Insufficient Verification of Data Authenticity in WP Hotel BookingCVE-2026-15152 0 The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner. Join the discussion | CVE Database V5 | 08/06/2026, 17:00:55 UTC Added: 08/06/2026, 22:13:09 UTC |
CVE-2026-15147: CWE-345 Insufficient Verification of Data Authenticity in Five Star Restaurant ReservationsCVE-2026-15147 0 The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed. Join the discussion | CVE Database V5 | 08/06/2026, 17:07:31 UTC Added: 08/06/2026, 22:13:09 UTC |
CVE-2026-14936: CWE-345 Insufficient Verification of Data Authenticity in Simple MembershipCVE-2026-14936 0 The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control. Join the discussion | CVE Database V5 | 08/06/2026, 17:04:20 UTC Added: 08/06/2026, 22:13:09 UTC |
Showing 1 to 10 of 43 results