We have discovered 3,327,117 live websites that are affected by CWE-639.
| 943,840 websites | |
| 340,448 websites | |
| 183,880 websites | |
| 148,973 websites | |
| 129,194 websites | |
| 112,677 websites | |
| 110,449 websites | |
| 99,217 websites | |
| 75,318 websites | |
| 68,033 websites |
| .com | 1,399,401 websites |
| .de | 196,875 websites |
| .org | 144,767 websites |
| .com.br | 105,141 websites |
| .nl | 99,662 websites |
| .it | 93,599 websites |
| .co.uk | 87,346 websites |
| .fr | 82,266 websites |
| .net | 73,201 websites |
| .pl | 57,337 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Apr, 2026 | CVE-2026-3371 | Tutor LMS <= 3.9.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification | 8,493 |
| Apr, 2026 | CVE-2026-32930 | Chamilo LMS has an IDOR in Gradebook Allows Cross-Course Evaluation Edit Without Ownership Check | 9 |
| Apr, 2026 | CVE-2026-33141 | Chamilo LMS has an IDOR in REST API Stats Endpoint Exposes Any User's Learning Data | 9 |
| Apr, 2026 | CVE-2026-33702 | Chamilo LMS has an Insecure Direct Object Reference (IDOR) | 9 |
| Apr, 2026 | CVE-2026-4654 | Awesome Support <= 6.3.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter | 1,282 |
| Apr, 2026 | CVE-2026-5167 | Masteriyo LMS <= 2.1.7 - Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint | 278 |
| Apr, 2026 | CVE-2026-5465 | Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter | 1,987 |
| Apr, 2026 | CVE-2026-4896 | WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation | 1,881 |
| Mar, 2026 | CVE-2026-3139 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field | 11,736 |
| Mar, 2026 | CVE-2026-3124 | Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' | 22,271 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Mar, 2026 | CVE-2026-1206 | Elementor Website Builder <= 3.35.7 - Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template | 2,559,160 |
| May, 2025 | CVE-2024-10075 | Jetpack < 13.8 - Unauthenticated Arbitrary Block & Shortcode Execution | 205,486 |
| Dec, 2025 | CVE-2025-15033 | WooCommerce - Subscriber/Customer+ Order Data Disclosure | 174,586 |
| Feb, 2026 | CVE-2025-13842 | Breadcrumb NavXT <= 7.5.0 - Missing Authorization to Sensitive Information Exposure | 102,717 |
| Dec, 2024 | CVE-2024-12335 | Avada Builder <= 3.11.12 - Authenticated (Contributor+) Protected Post Disclosure | 81,058 |
| Mar, 2026 | CVE-2026-2888 | Formidable Forms <= 6.28 - Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter | 59,936 |
| Dec, 2025 | CVE-2025-11924 | Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token | 58,840 |
| Mar, 2026 | CVE-2026-1992 | ExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation | 54,456 |
| Mar, 2026 | CVE-2026-2917 | Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Post Duplication via 'post_id' Parameter | 46,700 |
| Mar, 2026 | CVE-2026-2918 | Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Stored Cross-Site Scripting via Template Conditions | 46,700 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.io | *** | ||
| **************.de | *** | ||
| **********.com | *** | ||
| *******.com | *** | ||
| *********.com | *** | ||
| ************.org | *** | ||
| *****.com | *** | ||
| ******.*******.org | *** | ||
| **.*******.com | *** | ||
| ************.com | *,*** |