CWE-942— Permissive Cross-domain Policy with Untrusted Domains
83 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-942page 1 of 2
- CVE-2019-14860MEDIUMCVSS 6.5EG 6.52019-11-08
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
- CVE-2020-36851CRITICALCVSS 9.5EG 0.02025-09-25
Rob--W cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to make HTTP requests to arbitrary targets (SSRF). Because the proxy forwards requests and headers, an attacker can reach …
- CVE-2021-27786MEDIUMCVSS 4.6EG 9.82022-06-09
Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This request has an Origin header that identifies the domain that is making the initial request and defines the protocol between…
- CVE-2021-34435HIGHCVSS 8.8EG 8.82021-09-01
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happen…
- CVE-2022-22808HIGHCVSS 8.8EG 8.82022-02-09
A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections by…
- CVE-2022-26969CRITICALCVSS 9.8EG 9.82022-12-26
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
- CVE-2022-31736CRITICALCVSS 9.8EG 9.82022-12-22
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
- CVE-2022-34366MEDIUMCVSS 6.5EG 6.52023-02-10
Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.
- CVE-2022-47717HIGHCVSS 7.5EG 7.52023-02-01
Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
- CVE-2023-23128MEDIUMCVSS 6.1EG 6.12023-02-01
Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk…
- CVE-2023-23464HIGHCVSS 8.1EG 7.52023-02-15
Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow information disclosure.
- CVE-2023-2360HIGHCVSS 7.5EG 3.12023-04-28
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.
- CVE-2023-25603MEDIUMCVSS 5.4EG 5.42023-11-14
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive inf…
- CVE-2023-36829MEDIUMCVSS 6.8EG 6.82023-07-06
Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly returns the `access-control-allow-credentials: true` HTTP header if the `Origin` request he…
- CVE-2023-37401MEDIUMCVSS 5.3EG 5.32025-10-09
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be trusted.
- CVE-2023-37526MEDIUMCVSS 6.5EG 6.52024-05-14
HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any …
- CVE-2023-38122HIGHCVSS 7.2EG 7.22024-05-03
Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ig…
- CVE-2023-38125HIGHCVSS 8.8EG 7.52024-05-03
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Aut…
- CVE-2023-45213MEDIUMCVSS 6.6EG 6.62024-02-06
A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the device.
- CVE-2023-46098HIGHCVSS 8.0EG 8.02023-11-14
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, the products use an overly permissive CORS policy. This could allow an attacker to trick a legitima…
- CVE-2023-46281HIGHCVSS 7.1EG 7.12023-12-12
A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2407), Opcenter Quality (All versions < V2312), SIMATIC PCS neo (All versions < V4.1), SINEC NMS (All versions < V2.0 SP1), Totally Integrated Automation…
- CVE-2023-50940MEDIUMCVSS 5.3EG 5.32024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM …
- CVE-2024-10315MEDIUMCVSS 6.9EG 0.02024-11-11
In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.
- CVE-2024-11071HIGHCVSS 8.8EG 8.82025-04-07
Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions described below) which is developed and maintained by Cyberdigm may allow Cross-Site Request Forgery (CSRF) attack, wh…
- CVE-2024-21382MEDIUMCVSS 4.3EG 4.32024-01-26
Microsoft Edge for Android Information Disclosure Vulnerability
- CVE-2024-22348MEDIUMCVSS 5.3EG 5.32025-01-20
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not…
- CVE-2024-23823MEDIUMCVSS 4.2EG 4.22024-03-14
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for…
- CVE-2024-25124CRITICALCVSS 9.4EG 9.42024-02-21
Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting…
- CVE-2024-32862MEDIUMCVSS 6.8EG 6.82024-08-01
Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.
- CVE-2024-37131HIGHCVSS 7.5EG 7.52024-06-13
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious action…
- CVE-2024-41657HIGHCVSS 8.1EG 8.12024-08-20
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests t…
- CVE-2024-41659HIGHCVSS 8.1EG 8.12024-08-20
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking web…
- CVE-2024-45642MEDIUMCVSS 5.3EG 5.32024-11-14
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo…
- CVE-2024-49763HIGHCVSS 8.7EG 0.02024-12-02
PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking websit…
- CVE-2024-53276MEDIUMCVSS 6.3EG 0.02024-12-23
Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, an open CORS policy in app.js may allow an attacker to view the images of home-gallery when it is using the default sett…
- CVE-2024-6449MEDIUMCVSS 6.5EG 6.52024-08-28
HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon ope…
- CVE-2025-10529MEDIUMCVSS 6.5EG 6.52025-09-16
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
- CVE-2025-1083LOWCVSS 3.1EG 3.12025-02-06
A vulnerability classified as problematic was found in Mindskip xzs-mysql 学之思开源考试系统 3.9.0. Affected by this vulnerability is an unknown functionality of the component CORS Handler. The manipulation leads to permissive cro…
- CVE-2025-11304MEDIUMCVSS 6.3EG 6.32025-10-05
A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown functionality of the component API. Executing manipulation can lead to permissive cross-domain policy with untrusted domains. T…
- CVE-2025-13017HIGHCVSS 8.1EG 8.12025-11-11
Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
- CVE-2025-13019HIGHCVSS 8.1EG 8.12025-11-11
Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
- CVE-2025-13984MEDIUMCVSS 6.1EG 6.12026-01-28
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
- CVE-2025-25234HIGHCVSS 7.1EG 7.12025-04-17
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.
- CVE-2025-25264MEDIUMCVSS 6.5EG 8.82025-06-16
An unauthenticated remote attacker can trick an admin to visit a website containing malicious java script code. The current overly permissive CORS policy allows the attacker to obtain any files from the file system.
- CVE-2025-27909MEDIUMCVSS 5.4EG 5.42025-08-18
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could allow an attacker to carry out privileged actions as the domain name is not being limited to only trusted domains.
- CVE-2025-2865MEDIUMCVSS 6.1EG 6.12025-03-28
SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Thr…
- CVE-2025-30354MEDIUMCVSS 4.3EG 4.32025-04-01
Bruno is an open source IDE for exploring and testing APIs. A bug in the assertion runtime caused assert expressions to run in Developer Mode, even if Safe Mode was selected. The bug resulted in the sandbox settings to be ignored for the p…
- CVE-2025-41010MEDIUMCVSS 5.1EG 0.02025-10-02
Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin Resource Sharing (CORS) allows browsers to make cross-domain requests in a controlled manner. This request has an “Origin” header that identif…
- CVE-2025-41363MEDIUMCVSS 5.3EG 0.02025-06-06
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be…
- CVE-2025-41366MEDIUMCVSS 5.1EG 0.02025-06-06
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can on…
Map vulnerabilities like CWE-942 to your infrastructure
EchelonGraph correlates every CVE — across CWE-942 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →