CWE-302


Authentication Bypass by Assumed-Immutable Data

The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.


We have discovered 93 live websites that are affected by CWE-302.

Contact us to get more info









CVEs

  • Count - 2



Website Distribution by Country

Number of websites using CWE-302
United States24 websites



Germany36 websites
France14 websites
Switzerland2 websites
Italy2 websites
Russia2 websites
Australia1 websites
Bulgaria1 websites
Canada1 websites
Czech Republic1 websites

Website Distribution by TLD

Number of websites using CWE-302
.com28 websites
.org19 websites
.de8 websites
.net7 websites
.io4 websites
.eu3 websites
.ch2 websites
.ca1 websites
.co1 websites
.fi1 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-302
DiscoveredCVEDescriptionWebsites
Aug, 2026CVE-2026-77508 Weblate: Unverified REST API email changes89
Nov, 2023CVE-2023-47127 Weak Authentication in Session Handling in typo3/cms-core4
List of the most common CVEs that are part of CWE-302
DiscoveredCVEDescriptionWebsites
Aug, 2026CVE-2026-77508 Weblate: Unverified REST API email changes89
Nov, 2023CVE-2023-47127 Weak Authentication in Session Handling in typo3/cms-core4

Websites affected by CWE-302

Top websites that are affected by CWE-302. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.******************.org Germany***,***
*********.***********.com United States***,***
**************.de Germany***,***
****.*****.com Czech Republic***,***
*******.****.app United States*,***,***
*********.*******.org Singapore*,***,***
*********.*******.io United States*,***,***
*******.*****.im United States*,***,***
*********.********.org United States*,***,***
*********.*********.org France*,***,***
See full domain list