CWE-602Class

Client-Side Enforcement of Server-Side Security

Draft in the CWE catalog · 129 CVEs mapped

129
CVEs mapped
6.5
Median CVSS
What it is

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

Recent examples
none
CVE-2026-77999

CVE-2026-77999 - UNKNOWN Severity Vulnerability

Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (`_validateIPN()`) accepted `UNVERIFIED` and any non-`INVALID` response as valid, made its verification request with `CURLOPT_SSL_VERIFYPEER` disabled, and stored its verdict in a field nothing downstream ever checked — so processing continued regardless of the outcome. Separately, the paid-amount comparison only ran when `mc_gross` was a positive number; omitting the field from the POST body (`floatval(null) == 0`) skipped the check entirely. Combined with a merchant-configured `receiver_email` and a sequential, enumerable order id read from the `custom` field, an anonymous POST was enough to move a pending order straight to `CONFIRMED` with no payment, or force another customer's pending order to `FAILED`. `paypalv2.php` performed no amount check under any circumstances.

no explanation yet
0%
epss
7.3cvss
CVE-2026-84841

CVE-2026-84841 - HIGH Severity Vulnerability

A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.5.1 is able to resolve this issue. It is recommended to upgrade the affected component.

HIGHno explanation yet
0%
epss
5.3cvss
CVE-2026-77793

CVE-2026-77793 - MEDIUM Severity Vulnerability

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-602
Abstraction
Class
Structure
Simple
Status
Draft
References (2)