CWE-345


Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.


We have discovered 399,974 live websites that are affected by CWE-345.

Contact us to get more info









CVEs

  • Count - 12



Website Distribution by Country

Number of websites using CWE-345
United States136,930 websites



Germany28,234 websites
France21,417 websites
Singapore19,916 websites
Japan19,089 websites
Netherlands16,486 websites
Russia14,915 websites
Canada12,060 websites
Italy11,726 websites
Czech Republic8,976 websites

Website Distribution by TLD

Number of websites using CWE-345
.com175,208 websites
.org18,270 websites
.de16,919 websites
.net15,900 websites
.ru12,625 websites
.nl12,087 websites
.it9,775 websites
.cz7,378 websites
.fr6,626 websites
.co.uk5,725 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-345
DiscoveredCVEDescriptionWebsites
Apr, 2026CVE-2026-3177 Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook3,398
Mar, 2026CVE-2026-25921 Gogs: Cross-repository LFS object overwrite via missing content hash verification48
Feb, 2026CVE-2026-2428 Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modification98
Feb, 2026CVE-2026-2385 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay1,576
Feb, 2026CVE-2025-14444 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment947
Jan, 2026CVE-2026-0939 Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.2 - Unauthenticated Order Status Manipulation86
Apr, 2025CVE-2025-43865 React Router allows pre-render data spoofing on React-Router framework mode4
May, 2024CVE-2024-31341 WordPress User Profile Builder plugin <= 3.11.2 - Bypass Vulnerability vulnerability4,784
Mar, 2024CVE-2024-1321 EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass49
Feb, 2023CVE-2023-23941 SwagPayPal payment not sent to PayPal correctly1
List of the most common CVEs that are part of CWE-345
DiscoveredCVEDescriptionWebsites
Aug, 2020CVE-2020-11985 IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxyi...389,032
May, 2024CVE-2024-31341 WordPress User Profile Builder plugin <= 3.11.2 - Bypass Vulnerability vulnerability4,784
Apr, 2026CVE-2026-3177 Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook3,398
Feb, 2026CVE-2026-2385 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay1,576
Feb, 2026CVE-2025-14444 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment947
Feb, 2026CVE-2026-2428 Fluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modification98
Jan, 2026CVE-2026-0939 Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit <= 5.1.2 - Unauthenticated Order Status Manipulation86
Mar, 2024CVE-2024-1321 EventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment Bypass49
Mar, 2026CVE-2026-25921 Gogs: Cross-repository LFS object overwrite via missing content hash verification48
Nov, 2021CVE-2021-41203 Missing validation during checkpoint loading25

Websites affected by CWE-345

Top websites that are affected by CWE-345. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.****.us United States*,***
******************.com United States*,***
****.com United States*,***
********.com United States*,***
********.in India*,***
*.******.***.***.br Brazil*,***
*************.com GB*,***
*.*****.***.***.br Brazil*,***
******.com France*,***
**.***.edu United States*,***
See full domain list