CWE-914: Improper Control of Dynamically-Identified Variables
The product does not properly restrict reading from or writing to dynamically-identified variables.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-24914 — Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix t
- CVE-2025-14085 — youlaitech youlai-mall orders improper control of dynamically-identified variables
- CVE-2025-14051 — youlaitech youlai-mall addresses deleteAddress improper control of dynamically-identified variables
- CVE-2026-35173 — Chyrp Lite has an IDOR via Mass Assignment in Post Model
Recently published
- CVE-2026-35173 — Chyrp Lite has an IDOR via Mass Assignment in Post Model
- CVE-2025-14085 — youlaitech youlai-mall orders improper control of dynamically-identified variables
- CVE-2025-14051 — youlaitech youlai-mall addresses deleteAddress improper control of dynamically-identified variables
- CVE-2024-24914 — Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix t