CWE-472
138 CVEs • Abstraction: Base
External Control of Assumed-Immutable Web Parameter
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.
CVEs (138)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several produc...Show more |
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where...Show more |
IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improper input validation. IBM X-Force ID: 250396. |
3Debian FedoraprojectJnunemaker3Debian Linux FedoraHttpartyJul 14, 2026 Jan 4, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could resu...Show more |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleJun 17, 2026 May 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field. |
The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then requested by the webserver. We assume this service is used by the “meetings”-function where users can spe...Show more |
Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may not be sensitive and does not automatically mean a breach is likely to o...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the...Show more |
3Debian OpensuseOtrs4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 Jan 10, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This issue affects: ((OTRS)) Comm...Show more |
1Siemens 16Pxa30 W0 Firmware Pxa30 W1 FirmwarePxa30 W2 Firmware+13 moreJun 17, 2026 Dec 12, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX...Show more |
1Cambiumnetworks 5Cnpilot E400 Firmware Cnpilot E410 FirmwareCnpilot E600 Firmware+2 moreMay 13, 2026 Dec 20, 2017 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerability, accessible to all authenticated use...Show more |
1Cambiumnetworks 5Cnpilot E400 Firmware Cnpilot E410 FirmwareCnpilot E600 Firmware+2 moreMay 13, 2026 Dec 20, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the normal web administrative console for the 'user' account, the configuratio...Show more |