CWE-425: Forced Browsing
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
100 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-26689 — Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker
- CVE-2024-24592 — Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote atta
- CVE-2024-0204 — Authentication Bypass in GoAnywhere MFT
- CVE-2025-55736 — flaskBlog allows arbitrary privilege escalation
- CVE-2025-1542 — Improper permission control in OXARI ServiceDesk
- CVE-2025-48207 — The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
- CVE-2025-48205 — The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
- CVE-2025-48201 — The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
- CVE-2025-32367 — The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure D
- CVE-2025-15587 — Credentials exposure in tinycontrol devices
- CVE-2024-42001 — Vonets WiFi Bridges Forced Browsing
- CVE-2026-0650 — OpenFlagr <= 1.1.18 Authentication Bypass via Prefix Whitelist Path Normalization
- CVE-2026-34056 — OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data
- CVE-2024-39868 — A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not p
- CVE-2024-39867 — A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected devices do not p
- CVE-2026-10521 — Authenticated unintended access to critical program parameters
- CVE-2025-65011 — Unauthorized Access to files in WODESYS WD-R608U router
- CVE-2026-4900 — code-projects Online Food Ordering System localhost.sql privilege escalation
- CVE-2026-4532 — code-projects Simple Food Ordering System Database Backup food.sql file access
- CVE-2026-1978 — kalyan02 NanoCMS User Information pagesdata.txt direct request
Recently published
- CVE-2026-78051 — alexta69 MeTube Cookie File cookies.txt file access
- CVE-2026-14953 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to improper enforcement of role-based access control
- CVE-2026-76799 — code-projects Login Registration System SQL Database Backup login_registration_system.sql file access
- CVE-2026-19903 — SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
- CVE-2026-60011 — Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image
- CVE-2026-21760 — Unauthorized Access to Admin Functionality via Forced Browsing
- CVE-2024-23573 — HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13
- CVE-2026-13533 — agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access
- CVE-2026-10521 — Authenticated unintended access to critical program parameters
- CVE-2026-9610 — Multiple Vulnerabilities in IBM Datacap
- CVE-2026-34028 — Unauthenticated direct access to web data in Wertheim SafeController Software exposes files
- CVE-2026-11986 — Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak
- CVE-2026-8205 — Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in Calendar Block since action_get_events does not check canView on the calendar
- CVE-2026-7500 — Org.keycloak.keycloak-services: improper access control on keycloak server when the account account api feature is disabled
- CVE-2024-58343 — Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie d
- CVE-2026-4900 — code-projects Online Food Ordering System localhost.sql privilege escalation
- CVE-2026-34056 — OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data
- CVE-2026-34051 — OpenEMR has Improper ACL On Import/Export Popup
- CVE-2026-4532 — code-projects Simple Food Ordering System Database Backup food.sql file access
- CVE-2026-32867 — OPEXUS eComplaint unauthenticated file upload