CWE-345: Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
428 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-66570 — cpp-httplib Untrusted HTTP Header Handling: Internal Header Shadowing (REMOTE*/LOCAL*)
- CVE-2025-66255 — Unauthenticated Arbitrary File Upload (upgrade_contents.php)
- CVE-2024-23601 — A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A speciall
- CVE-2025-59934 — Formbricks missing JWT signature verification
- CVE-2026-25921 — Gogs: Cross-repository LFS object overwrite via missing content hash verification
- CVE-2025-66016 — CGGMP24 is missing a check in the ZK proof used in CGGMP21
- CVE-2025-54792 — LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
- CVE-2026-4478 — Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification
- CVE-2025-7096 — Comodo Internet Security Premium Manifest File cis_update_x64.xml integrity check
- CVE-2026-23966 — sm-crypto Affected by Private Key Recovery in SM2-PKE
- CVE-2025-48865 — Fabio allows HTTP clients to manipulate custom headers it adds
- CVE-2026-24772 — OpenProject has SSRF and CSWSH in Hocuspocus Synchronization Server
- CVE-2026-30223 — OliveTin: JWT Audience Validation Bypass in Local Key and HMAC Modes
- CVE-2025-49199 — Backup files can be modified and uploaded
- CVE-2026-33143 — OneUptime: WhatsApp Webhook Missing Signature Verification
- CVE-2025-66225 — OrangeHRM is Vulnerable to Account Takeover Through Unvalidated Username in Password Reset Workflow
- CVE-2025-21606 — Local Privilege Escalation via Exposed XPC Method Due to Client Verification Failure in stats
- CVE-2026-30920 — OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding
- CVE-2025-9379 — Belkin AX1800 Firmware Update data authenticity
- CVE-2025-27616 — Vela Server has Insufficient Webhook Payload Data Verification
Recently published
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-73316 — XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider
- CVE-2026-85008 — undici vulnerable to caching and replay of unsafe HTTP method responses
- CVE-2026-85621 — LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu
- CVE-2026-85435 — MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment
- CVE-2026-85434 — MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping
- CVE-2026-85431 — MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection
- CVE-2026-85430 — MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing
- CVE-2026-85429 — MOOS-IvP through 24.8.1 uFldNodeComms Node Message Source Spoofing
- CVE-2026-53728 — Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
- CVE-2026-84767 — WordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerability
- CVE-2023-20576 — Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially result
- CVE-2026-20355 — Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty
- CVE-2026-19219 — DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
- CVE-2026-82813 — BEN Group TubeBuddy for YouTube Extension tubebuddymaster1.js TBGlobal.GetToken data authenticity
- CVE-2026-82811 — Toggl OÜ Toggl Track Extension postMessage origin validation
- CVE-2026-82858 — @hulumi/drift before 1.3.2 Unsafe Execute Plan Acceptance
- CVE-2026-19410 — Google Cloud Build Comment Control Bypass via Webhook Suppression
- CVE-2026-82549 — Linux Foundation Magma SecurityModeComplete integrity check
- CVE-2026-82465 — pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest
More specific weaknesses
- CWE-1293 — Missing Source Correlation of Multiple Independent Data
- CWE-346 — Origin Validation Error
- CWE-347 — Improper Verification of Cryptographic Signature
- CWE-348 — Use of Less Trusted Source
- CWE-349 — Acceptance of Extraneous Untrusted Data With Trusted Data
- CWE-351 — Insufficient Type Distinction
- CWE-352 — CSRF
- CWE-353 — Missing Support for Integrity Check
- CWE-354 — Improper Validation of Integrity Check Value
- CWE-360 — Trust of System Event Data
- CWE-494 — Download of Code Without Integrity Check
- CWE-616 — PHP
- CWE-646 — Reliance on File Name or Extension of Externally-Supplied File
- CWE-649 — Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking
- CWE-924 — Improper Enforcement of Message Integrity During Transmission in a Communication Channel