CWE-288
658 CVEs • Abstraction: Base
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
CVEs (658)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to lis...Show more |
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation.
This issue affects MStore API: from n/a through 4.18.4. |
Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions. |
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. |
Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions. |
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. |
Unauthenticated Broken Authentication in Booknetic <= 4.8.5 versions. |
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authent...Show more |
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. |
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions. |
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. |
Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions. |
Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions. |
Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions. |
Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions. |
Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions. |
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions. |
Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions. |
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation.
This issue affects Faust.Js: from n/a through 1.8.7. |
1Nuxt 2Nuxt Nuxt/nitro ServerJun 17, 2026 Jun 12, 2026 6.3 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before...Show more |