#CWE-287
All CosmicBytez Labs articles tagged #CWE-287, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-59500: Priority Portal Generator Authentication Bypass — CVSS 10.0
Maximum severity CVE in Priority ERP's portal addon allows unauthenticated remote attackers to bypass authentication entirely. Patch immediately.
- Security
CVE-2026-14205: WP Events Manager Plugin Allows Fraudulent Paid Event Bookings via Payment Bypass
A critical improper authentication vulnerability in WP Events Manager for WordPress allows unauthenticated attackers to register for paid events without...
- Security
CVE-2026-12492: WooCommerce OTP Login Plugin Auth Bypass — Full Admin Takeover
The Happy Coders OTP Login for WooCommerce plugin before 2.8 allows unauthenticated attackers to bypass OTP verification and log in as any WordPress user,...
- Security
CVE-2026-12183: Critical Auth Bypass in Gas Station Automation System
A CVSS 9.8 authentication bypass in Nefteprodukttekhnika's BUK TS-G Gas Station Automation System allows any unauthenticated attacker to gain full...
- Security
CVE-2026-35051: Traefik ForwardAuth Authentication Bypass
A critical CVSS 10.0 authentication bypass in Traefik's ForwardAuth middleware allows attackers to circumvent authentication when the proxy is deployed...
- Security
KodExplorer fileGet Auth Bypass — Unauthenticated Remote
KodExplorer versions up to 4.52 contain an improper authentication flaw in the fileGet endpoint that allows remote attackers to access files without valid...